CVE-2004-1029
Summary
| CVE | CVE-2004-1029 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-03-01 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Conectiva | Linux | 10.0 | All | All | All |
| Operating System | Gentoo | Linux | All | All | All | All |
| Operating System | Hp | Hp-ux | 11.00 | All | All | All |
| Operating System | Hp | Hp-ux | 11.11 | All | All | All |
| Operating System | Hp | Hp-ux | 11.22 | All | All | All |
| Operating System | Hp | Hp-ux | 11.23 | All | ia64_64-bit | All |
| Application | Hp | Java Sdk-rte | 1.3 | All | hp-ux_pa-risc | All |
| Application | Hp | Java Sdk-rte | 1.4 | All | hp-ux_pa-risc | All |
| Application | Sun | Jdk | 1.3.1_01 | All | linux | All |
| Application | Sun | Jdk | 1.3.1_01 | All | solaris | All |
| Application | Sun | Jdk | 1.3.1_01a | All | windows | All |
| Application | Sun | Jdk | 1.3.1_02 | All | linux | All |
| Application | Sun | Jdk | 1.3.1_02 | All | solaris | All |
| Application | Sun | Jdk | 1.3.1_02 | All | windows | All |
| Application | Sun | Jdk | 1.3.1_03 | All | linux | All |
| Application | Sun | Jdk | 1.3.1_03 | All | solaris | All |
| Application | Sun | Jdk | 1.3.1_03 | All | windows | All |
| Application | Sun | Jdk | 1.3.1_04 | All | windows | All |
| Application | Sun | Jdk | 1.3.1_05 | All | linux | All |
| Application | Sun | Jdk | 1.3.1_05 | All | solaris | All |
| Application | Sun | Jdk | 1.3.1_05 | All | windows | All |
| Application | Sun | Jdk | 1.3.1_06 | All | linux | All |
| Application | Sun | Jdk | 1.3.1_06 | All | solaris | All |
| Application | Sun | Jdk | 1.3.1_06 | All | windows | All |
| Application | Sun | Jdk | 1.3.1_07 | All | linux | All |
| Application | Sun | Jdk | 1.3.1_07 | All | solaris | All |
| Application | Sun | Jdk | 1.3.1_07 | All | windows | All |
| Application | Sun | Jdk | 1.4 | All | linux | All |
| Application | Sun | Jdk | 1.4 | All | solaris | All |
| Application | Sun | Jdk | 1.4 | All | windows | All |
| Application | Sun | Jdk | 1.4.0_01 | All | windows | All |
| Application | Sun | Jdk | 1.4.0_02 | All | linux | All |
| Application | Sun | Jdk | 1.4.0_02 | All | solaris | All |
| Application | Sun | Jdk | 1.4.0_02 | All | windows | All |
| Application | Sun | Jdk | 1.4.0_03 | All | linux | All |
| Application | Sun | Jdk | 1.4.0_03 | All | solaris | All |
| Application | Sun | Jdk | 1.4.0_03 | All | windows | All |
| Application | Sun | Jdk | 1.4.0_4 | All | linux | All |
| Application | Sun | Jdk | 1.4.0_4 | All | solaris | All |
| Application | Sun | Jdk | 1.4.0_4 | All | windows | All |
| Application | Sun | Jdk | 1.4.1 | All | linux | All |
| Application | Sun | Jdk | 1.4.1 | All | solaris | All |
| Application | Sun | Jdk | 1.4.1 | All | windows | All |
| Application | Sun | Jdk | 1.4.1_01 | All | linux | All |
| Application | Sun | Jdk | 1.4.1_01 | All | solaris | All |
| Application | Sun | Jdk | 1.4.1_01 | All | windows | All |
| Application | Sun | Jdk | 1.4.1_02 | All | linux | All |
| Application | Sun | Jdk | 1.4.1_02 | All | solaris | All |
| Application | Sun | Jdk | 1.4.1_02 | All | windows | All |
| Application | Sun | Jdk | 1.4.1_03 | All | linux | All |
| Application | Sun | Jdk | 1.4.1_03 | All | solaris | All |
| Application | Sun | Jdk | 1.4.1_03 | All | windows | All |
| Application | Sun | Jdk | 1.4.2 | All | linux | All |
| Application | Sun | Jdk | 1.4.2 | All | solaris | All |
| Application | Sun | Jdk | 1.4.2 | All | windows | All |
| Application | Sun | Jdk | 1.4.2_01 | All | linux | All |
| Application | Sun | Jdk | 1.4.2_02 | All | linux | All |
| Application | Sun | Jdk | 1.4.2_03 | All | linux | All |
| Application | Sun | Jdk | 1.4.2_03 | All | solaris | All |
| Application | Sun | Jdk | 1.4.2_03 | All | windows | All |
| Application | Sun | Jdk | 1.4.2_04 | All | linux | All |
| Application | Sun | Jdk | 1.4.2_04 | All | solaris | All |
| Application | Sun | Jdk | 1.4.2_04 | All | windows | All |
| Application | Sun | Jdk | 1.4.2_05 | All | linux | All |
| Application | Sun | Jdk | 1.4.2_05 | All | solaris | All |
| Application | Sun | Jdk | 1.4.2_05 | All | windows | All |
| Application | Sun | Jre | 1.3.0 | All | linux | All |
| Application | Sun | Jre | 1.3.0 | All | solaris | All |
| Application | Sun | Jre | 1.3.0 | All | windows | All |
| Application | Sun | Jre | 1.3.0 | update1 | linux | All |
| Application | Sun | Jre | 1.3.0 | update2 | linux | All |
| Application | Sun | Jre | 1.3.0 | update2 | solaris | All |
| Application | Sun | Jre | 1.3.0 | update2 | windows | All |
| Application | Sun | Jre | 1.3.0 | update3 | linux | All |
| Application | Sun | Jre | 1.3.0 | update4 | linux | All |
| Application | Sun | Jre | 1.3.0 | update4 | windows | All |
| Application | Sun | Jre | 1.3.0 | update5 | linux | All |
| Application | Sun | Jre | 1.3.0 | update5 | solaris | All |
| Application | Sun | Jre | 1.3.0 | update5 | windows | All |
| Application | Sun | Jre | 1.3.1 | All | linux | All |
| Application | Sun | Jre | 1.3.1 | update1 | linux | All |
| Application | Sun | Jre | 1.3.1 | update1 | solaris | All |
| Application | Sun | Jre | 1.3.1 | update1 | windows | All |
| Application | Sun | Jre | 1.3.1 | update1a | windows | All |
| Application | Sun | Jre | 1.3.1 | update4 | solaris | All |
| Application | Sun | Jre | 1.3.1 | update4 | windows | All |
| Application | Sun | Jre | 1.3.1 | update8 | linux | All |
| Application | Sun | Jre | 1.3.1 | update8 | solaris | All |
| Application | Sun | Jre | 1.3.1 | update8 | windows | All |
| Application | Sun | Jre | 1.3.1_02 | All | linux | All |
| Application | Sun | Jre | 1.3.1_02 | All | solaris | All |
| Application | Sun | Jre | 1.3.1_02 | All | windows | All |
| Application | Sun | Jre | 1.3.1_03 | All | linux | All |
| Application | Sun | Jre | 1.3.1_03 | All | solaris | All |
| Application | Sun | Jre | 1.3.1_03 | All | windows | All |
| Application | Sun | Jre | 1.3.1_05 | All | linux | All |
| Application | Sun | Jre | 1.3.1_05 | All | solaris | All |
| Application | Sun | Jre | 1.3.1_05 | All | windows | All |
| Application | Sun | Jre | 1.3.1_06 | All | linux | All |
| Application | Sun | Jre | 1.3.1_06 | All | solaris | All |
| Application | Sun | Jre | 1.3.1_06 | All | windows | All |
| Application | Sun | Jre | 1.3.1_07 | All | linux | All |
| Application | Sun | Jre | 1.3.1_07 | All | solaris | All |
| Application | Sun | Jre | 1.3.1_07 | All | windows | All |
| Application | Sun | Jre | 1.3.1_09 | All | linux | All |
| Application | Sun | Jre | 1.3.1_09 | All | solaris | All |
| Application | Sun | Jre | 1.3.1_09 | All | windows | All |
| Application | Sun | Jre | 1.4 | All | linux | All |
| Application | Sun | Jre | 1.4 | All | solaris | All |
| Application | Sun | Jre | 1.4 | All | windows | All |
| Application | Sun | Jre | 1.4.0_01 | All | solaris | All |
| Application | Sun | Jre | 1.4.0_01 | All | windows | All |
| Application | Sun | Jre | 1.4.0_02 | All | linux | All |
| Application | Sun | Jre | 1.4.0_02 | All | solaris | All |
| Application | Sun | Jre | 1.4.0_02 | All | windows | All |
| Application | Sun | Jre | 1.4.0_03 | All | linux | All |
| Application | Sun | Jre | 1.4.0_03 | All | solaris | All |
| Application | Sun | Jre | 1.4.0_03 | All | windows | All |
| Application | Sun | Jre | 1.4.0_04 | All | linux | All |
| Application | Sun | Jre | 1.4.0_04 | All | solaris | All |
| Application | Sun | Jre | 1.4.0_04 | All | windows | All |
| Application | Sun | Jre | 1.4.1 | All | linux | All |
| Application | Sun | Jre | 1.4.1 | All | solaris | All |
| Application | Sun | Jre | 1.4.1 | All | windows | All |
| Application | Sun | Jre | 1.4.1 | update3 | linux | All |
| Application | Sun | Jre | 1.4.1 | update3 | solaris | All |
| Application | Sun | Jre | 1.4.1 | update3 | windows | All |
| Application | Sun | Jre | 1.4.1_01 | All | linux | All |
| Application | Sun | Jre | 1.4.1_01 | All | solaris | All |
| Application | Sun | Jre | 1.4.1_01 | All | windows | All |
| Application | Sun | Jre | 1.4.1_02 | All | linux | All |
| Application | Sun | Jre | 1.4.1_02 | All | solaris | All |
| Application | Sun | Jre | 1.4.1_02 | All | windows | All |
| Application | Sun | Jre | 1.4.1_07 | All | windows | All |
| Application | Sun | Jre | 1.4.2 | All | linux | All |
| Application | Sun | Jre | 1.4.2 | All | solaris | All |
| Application | Sun | Jre | 1.4.2 | All | windows | All |
| Application | Sun | Jre | 1.4.2 | update1 | linux | All |
| Application | Sun | Jre | 1.4.2 | update1 | solaris | All |
| Application | Sun | Jre | 1.4.2 | update1 | windows | All |
| Application | Sun | Jre | 1.4.2 | update2 | linux | All |
| Application | Sun | Jre | 1.4.2 | update2 | solaris | All |
| Application | Sun | Jre | 1.4.2 | update2 | windows | All |
| Application | Sun | Jre | 1.4.2 | update3 | linux | All |
| Application | Sun | Jre | 1.4.2 | update3 | solaris | All |
| Application | Sun | Jre | 1.4.2 | update3 | windows | All |
| Application | Sun | Jre | 1.4.2 | update4 | linux | All |
| Application | Sun | Jre | 1.4.2 | update4 | solaris | All |
| Application | Sun | Jre | 1.4.2 | update4 | windows | All |
| Application | Sun | Jre | 1.4.2 | update5 | linux | All |
| Application | Sun | Jre | 1.4.2 | update5 | solaris | All |
| Application | Sun | Jre | 1.4.2 | update5 | windows | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | All | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | windows_2000_nt | All |
| Hardware | Symantec | Gateway Security 5400 | 2.0 | All | All | All |
| Hardware | Symantec | Gateway Security 5400 | 2.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| APPLE-SA-2005-02-22 Security Update 2005-002 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| IBM Lotus Notes Java Plug-in Sandbox Security Bypass - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| SecurityReason - HP-UX Java Web Start remote unauthorized privileged access | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Sun Java Plug-in Multiple Applet Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| java-1_4_2-sun-src-1.4.2.08-0.1.i586 RPM | af854a3a-2127-422b-91ae-364da2661108 | rpmfind.net | |
| Secunia - Advisories - Sun Java Plug-in Sandbox Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Vulnerability Note VU#760344 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| iDEFENSE | af854a3a-2127-422b-91ae-364da2661108 | www.idefense.com | |
| #57591: Security Vulnerability With Java Plug-in in JRE/SDK | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch, Vendor Advisory |
| Klikki Oy - Sun Java Plugin vulnerability | af854a3a-2127-422b-91ae-364da2661108 | jouko.iki.fi | |
| #101523: Security Vulnerability With Java Plug-in in JRE/SDK (formerly Document ID: 57591) | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.