{"api_version":"1","generated_at":"2026-07-23T09:51:52+00:00","cve":"CVE-2002-1290","urls":{"html":"https://cve.report/CVE-2002-1290","api":"https://cve.report/api/cve/CVE-2002-1290.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1290","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1290"},"summary":{"title":"CVE-2002-1290","description":"The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-11-29 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=103682630823080&w=2","name":"http://marc.info/?l=bugtraq&m=103682630823080&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.iss.net/security_center/static/10583.php","name":"http://www.iss.net/security_center/static/10583.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: msvm-inativeservices-clipboard-access (10583): Microsoft VM INativeServices could be used to access clipboard contents","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6132","name":"http://www.securityfocus.com/bid/6132","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft JVM Unauthorized Clipboard Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=ntbugtraq&m=103684360031565&w=2","name":"http://marc.info/?l=ntbugtraq&m=103684360031565&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1290","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1290","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1290","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"java_virtual_machine","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:19:28.492Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"6132","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6132"},{"name":"20021108 Technical information about unpatched MS Java vulnerabilities","tags":["mailing-list","x_refsource_NTBUGTRAQ","x_transferred"],"url":"http://marc.info/?l=ntbugtraq&m=103684360031565&w=2"},{"name":"msvm-inativeservices-clipboard-access(10583)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10583.php"},{"name":"20021108 Technical information about unpatched MS Java vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=103682630823080&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-11-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"6132","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6132"},{"name":"20021108 Technical information about unpatched MS Java vulnerabilities","tags":["mailing-list","x_refsource_NTBUGTRAQ"],"url":"http://marc.info/?l=ntbugtraq&m=103684360031565&w=2"},{"name":"msvm-inativeservices-clipboard-access(10583)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10583.php"},{"name":"20021108 Technical information about unpatched MS Java vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=103682630823080&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1290","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"6132","refsource":"BID","url":"http://www.securityfocus.com/bid/6132"},{"name":"20021108 Technical information about unpatched MS Java vulnerabilities","refsource":"NTBUGTRAQ","url":"http://marc.info/?l=ntbugtraq&m=103684360031565&w=2"},{"name":"msvm-inativeservices-clipboard-access(10583)","refsource":"XF","url":"http://www.iss.net/security_center/static/10583.php"},{"name":"20021108 Technical information about unpatched MS Java vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=103682630823080&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1290","datePublished":"2002-11-14T05:00:00.000Z","dateReserved":"2002-11-13T00:00:00.000Z","dateUpdated":"2024-08-08T03:19:28.492Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-11-29 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:java_virtual_machine:1.1:*:*:*:*:*:*:*","matchCriteriaId":"916DA8F3-677B-46CB-A2B9-9FE2A2EBEBAD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1290","Ordinal":"1","Title":"CVE-2002-1290","CVE":"CVE-2002-1290","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1290","Ordinal":"1","NoteData":"The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class.","Type":"Description","Title":"CVE-2002-1290"},{"CveYear":"2002","CveId":"1290","Ordinal":"2","NoteData":"2002-11-14","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1290","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}