Sun Java Runtime Environment Java Plug-in JavaScript Security Restriction Bypass Vulnerability

BID:11726

Info

Sun Java Runtime Environment Java Plug-in JavaScript Security Restriction Bypass Vulnerability

Bugtraq ID: 11726
Class: Access Validation Error
CVE: CVE-2004-1029
Remote: Yes
Local: No
Published: Nov 22 2004 12:00AM
Updated: Jul 12 2009 08:06AM
Credit: Discovery of this vulnerability is credited to Jouko Pynnonen <[email protected]>.
Vulnerable: Symantec Gateway Security 5400 2.0.1
Symantec Gateway Security 5400 2.0
Symantec Enterprise Firewall 8.0 Solaris
Symantec Enterprise Firewall 8.0 NT/2000
Symantec Enterprise Firewall 8.0
SuSE Linux 8.1
SuSE Linux 8.0 i386
SuSE Linux 8.0
Sun SDK (Windows Production Release) 1.4.2 _05
Sun SDK (Windows Production Release) 1.4.2 _04
Sun SDK (Windows Production Release) 1.4.2 _03
Sun SDK (Windows Production Release) 1.4.2
Sun SDK (Windows Production Release) 1.4.1 _03
Sun SDK (Windows Production Release) 1.4.1 _02
Sun SDK (Windows Production Release) 1.4.1 _01
Sun SDK (Windows Production Release) 1.4.1
Sun SDK (Windows Production Release) 1.4 .0_4
Sun SDK (Windows Production Release) 1.4 .0_03
Sun SDK (Windows Production Release) 1.4 .0_02
Sun SDK (Windows Production Release) 1.4 .0_01
Sun SDK (Windows Production Release) 1.4
Sun SDK (Windows Production Release) 1.3.1 _07
Sun SDK (Windows Production Release) 1.3.1 _06
Sun SDK (Windows Production Release) 1.3.1 _05
Sun SDK (Windows Production Release) 1.3.1 _04
Sun SDK (Windows Production Release) 1.3.1 _03
Sun SDK (Windows Production Release) 1.3.1 _02
Sun SDK (Windows Production Release) 1.3.1 _01a
Sun SDK (Solaris Production Release) 1.4.2 _05
Sun SDK (Solaris Production Release) 1.4.2 _04
Sun SDK (Solaris Production Release) 1.4.2 _03
Sun SDK (Solaris Production Release) 1.4.2
Sun SDK (Solaris Production Release) 1.4.1 _03
Sun SDK (Solaris Production Release) 1.4.1 _02
Sun SDK (Solaris Production Release) 1.4.1 _01
Sun SDK (Solaris Production Release) 1.4.1
Sun SDK (Solaris Production Release) 1.4 .0_4
Sun SDK (Solaris Production Release) 1.4 .0_03
Sun SDK (Solaris Production Release) 1.4 .0_02
Sun SDK (Solaris Production Release) 1.4
Sun SDK (Solaris Production Release) 1.3.1 _07
Sun SDK (Solaris Production Release) 1.3.1 _06
Sun SDK (Solaris Production Release) 1.3.1 _05
Sun SDK (Solaris Production Release) 1.3.1 _03
Sun SDK (Solaris Production Release) 1.3.1 _02
Sun SDK (Solaris Production Release) 1.3.1 _01
Sun SDK (Linux Production Release) 1.4.2 _05
Sun SDK (Linux Production Release) 1.4.2 _04
Sun SDK (Linux Production Release) 1.4.2 _03
Sun SDK (Linux Production Release) 1.4.2 _02
Sun SDK (Linux Production Release) 1.4.2 _01
Sun SDK (Linux Production Release) 1.4.2
Sun SDK (Linux Production Release) 1.4.1 _03
Sun SDK (Linux Production Release) 1.4.1 _02
Sun SDK (Linux Production Release) 1.4.1 _01
Sun SDK (Linux Production Release) 1.4.1
Sun SDK (Linux Production Release) 1.4 .0_4
Sun SDK (Linux Production Release) 1.4 .0_03
Sun SDK (Linux Production Release) 1.4 .0_02
Sun SDK (Linux Production Release) 1.4
Sun SDK (Linux Production Release) 1.3.1 _07
Sun SDK (Linux Production Release) 1.3.1 _06
Sun SDK (Linux Production Release) 1.3.1 _05
Sun SDK (Linux Production Release) 1.3.1 _03
Sun SDK (Linux Production Release) 1.3.1 _02
Sun SDK (Linux Production Release) 1.3.1 _01
Sun JRE (Windows Production Release) 1.4.2 _05
Sun JRE (Windows Production Release) 1.4.2 _04
Sun JRE (Windows Production Release) 1.4.2 _03
Sun JRE (Windows Production Release) 1.4.2 _02
Sun JRE (Windows Production Release) 1.4.2 _01
Sun JRE (Windows Production Release) 1.4.2
Sun JRE (Windows Production Release) 1.4.1 _07
Sun JRE (Windows Production Release) 1.4.1 _03
Sun JRE (Windows Production Release) 1.4.1 _02
Sun JRE (Windows Production Release) 1.4.1 _01
Sun JRE (Windows Production Release) 1.4.1
Sun JRE (Windows Production Release) 1.4 .0_04
Sun JRE (Windows Production Release) 1.4 .0_03
Sun JRE (Windows Production Release) 1.4 .0_02
Sun JRE (Windows Production Release) 1.4 .0_01
Sun JRE (Windows Production Release) 1.4
Sun JRE (Windows Production Release) 1.3.1 _09
Sun JRE (Windows Production Release) 1.3.1 _08
Sun JRE (Windows Production Release) 1.3.1 _07
Sun JRE (Windows Production Release) 1.3.1 _06
Sun JRE (Windows Production Release) 1.3.1 _05
Sun JRE (Windows Production Release) 1.3.1 _04
Sun JRE (Windows Production Release) 1.3.1 _03
Sun JRE (Windows Production Release) 1.3.1 _02
Sun JRE (Windows Production Release) 1.3.1 _01a
Sun JRE (Windows Production Release) 1.3.1 _01
Sun JRE (Windows Production Release) 1.3 .0_05
Sun JRE (Windows Production Release) 1.3 .0_04
Sun JRE (Windows Production Release) 1.3 .0_02
Sun JRE (Windows Production Release) 1.3 .0_02
Sun JRE (Windows Production Release) 1.3
Sun JRE (Solaris Production Release) 1.4.2 _05
Sun JRE (Solaris Production Release) 1.4.2 _04
Sun JRE (Solaris Production Release) 1.4.2 _03
Sun JRE (Solaris Production Release) 1.4.2 _02
Sun JRE (Solaris Production Release) 1.4.2 _01
Sun JRE (Solaris Production Release) 1.4.2
Sun JRE (Solaris Production Release) 1.4.1 _03
Sun JRE (Solaris Production Release) 1.4.1 _02
Sun JRE (Solaris Production Release) 1.4.1 _01
Sun JRE (Solaris Production Release) 1.4.1
Sun JRE (Solaris Production Release) 1.4 .0_04
Sun JRE (Solaris Production Release) 1.4 .0_04
Sun JRE (Solaris Production Release) 1.4 .0_03
Sun JRE (Solaris Production Release) 1.4 .0_02
Sun JRE (Solaris Production Release) 1.4 .0_01
Sun JRE (Solaris Production Release) 1.4
Sun JRE (Solaris Production Release) 1.3.1 _09
Sun JRE (Solaris Production Release) 1.3.1 _08
Sun JRE (Solaris Production Release) 1.3.1 _07
Sun JRE (Solaris Production Release) 1.3.1 _06
Sun JRE (Solaris Production Release) 1.3.1 _05
Sun JRE (Solaris Production Release) 1.3.1 _04
Sun JRE (Solaris Production Release) 1.3.1 _03
+ Macromedia ColdFusion Server MX Professional
+ Macromedia ColdFusion Server MX Enterprise
+ Macromedia ColdFusion Server MX Developer
Sun JRE (Solaris Production Release) 1.3.1 _02
Sun JRE (Solaris Production Release) 1.3.1 _01
Sun JRE (Solaris Production Release) 1.3.1
Sun JRE (Solaris Production Release) 1.3 _04
Sun JRE (Solaris Production Release) 1.3 _03
Sun JRE (Solaris Production Release) 1.3 _01
Sun JRE (Solaris Production Release) 1.3 .0_05
Sun JRE (Solaris Production Release) 1.3 .0_02
Sun JRE (Solaris Production Release) 1.3 .0_02
Sun JRE (Solaris Production Release) 1.3
Sun JRE (Linux Production Release) 1.4.2 _05
Sun JRE (Linux Production Release) 1.4.2 _04
+ Opera Software Opera Web Browser 7.54
Sun JRE (Linux Production Release) 1.4.2 _03
Sun JRE (Linux Production Release) 1.4.2 _02
Sun JRE (Linux Production Release) 1.4.2 _01
Sun JRE (Linux Production Release) 1.4.2
Sun JRE (Linux Production Release) 1.4.1 _03
Sun JRE (Linux Production Release) 1.4.1 _02
Sun JRE (Linux Production Release) 1.4.1 _01
Sun JRE (Linux Production Release) 1.4.1
Sun JRE (Linux Production Release) 1.4 .0_04
Sun JRE (Linux Production Release) 1.4 .0_03
Sun JRE (Linux Production Release) 1.4 .0_02
Sun JRE (Linux Production Release) 1.4
Sun JRE (Linux Production Release) 1.3.1 _09
Sun JRE (Linux Production Release) 1.3.1 _08
Sun JRE (Linux Production Release) 1.3.1 _07
Sun JRE (Linux Production Release) 1.3.1 _06
Sun JRE (Linux Production Release) 1.3.1 _05
Sun JRE (Linux Production Release) 1.3.1 _04
Sun JRE (Linux Production Release) 1.3.1 _03
Sun JRE (Linux Production Release) 1.3.1 _02
Sun JRE (Linux Production Release) 1.3.1 _01a
Sun JRE (Linux Production Release) 1.3.1 _01
Sun JRE (Linux Production Release) 1.3.1
Sun JRE (Linux Production Release) 1.3 .0_05
Sun JRE (Linux Production Release) 1.3 .0_04
Sun JRE (Linux Production Release) 1.3 .0_03
Sun JRE (Linux Production Release) 1.3 .0_02
Sun JRE (Linux Production Release) 1.3 .0_01
Sun JRE (Linux Production Release) 1.3 .0
Sun Java Desktop System (JDS) 2.0
Sun Java Desktop System (JDS) 2003
Sun Java 2 Runtime Environment 1.4.2
Sun Java 2 Runtime Environment 1.4.1
Sun Java 2 Runtime Environment 1.3.1 _08
Sun Java 2 Runtime Environment 1.3.1 _01
Sun Java 2 Runtime Environment 1.3 _05
Sun Java 2 Runtime Environment 1.3 _02
Sun Java 2 Runtime Environment 1.3
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
Oracle Workflow 11.5.9 .5
Oracle Workflow 11.5.1
Oracle Oracle9i Standard Edition 9.2 .6
Oracle Oracle9i Standard Edition 9.2 .0.5
Oracle Oracle9i Standard Edition 9.0.1 .5
Oracle Oracle9i Standard Edition 9.0.1 .4
Oracle Oracle9i Personal Edition 9.2 .6
Oracle Oracle9i Personal Edition 9.2 .0.5
Oracle Oracle9i Personal Edition 9.0.1 .5
Oracle Oracle9i Personal Edition 9.0.1 .4
Oracle Oracle9i Enterprise Edition 9.2 .6.0
Oracle Oracle9i Enterprise Edition 9.2 .0.5
Oracle Oracle9i Enterprise Edition 9.0.1 .5
Oracle Oracle9i Enterprise Edition 9.0.1 .4
Oracle Oracle9i Application Server 9.0.3 .1
Oracle Oracle9i Application Server 9.0.2 .3
Oracle Oracle9i Application Server 1.0.2 .2
Oracle Oracle8i Standard Edition 8.1.7 .4
Oracle Oracle8i Enterprise Edition 8.1.7 .4.0
Oracle Oracle8 8.0.6 .3
Oracle Oracle8 8.0.6
Oracle Oracle10g Standard Edition 10.1 .0.4
Oracle Oracle10g Standard Edition 10.1 .0.3
Oracle Oracle10g Standard Edition 10.1 .0.2
Oracle Oracle10g Personal Edition 10.1 .0.4
Oracle Oracle10g Personal Edition 10.1 .0.3
Oracle Oracle10g Personal Edition 10.1 .0.2
Oracle Oracle10g Enterprise Edition 10.1 .0.4
Oracle Oracle10g Enterprise Edition 10.1 .0.3
Oracle Oracle10g Enterprise Edition 10.1 .0.2
Oracle Oracle10g Application Server 9.0.4 .1
Oracle Oracle10g Application Server 9.0.4 .0
Oracle Oracle HTTP Server for Apps only 1.0.2 .1s
Oracle Oracle HTTP Server 9.2 .0
+ Apache Apache 1.3.22
Oracle Oracle HTTP Server 9.1
+ Apache Apache 1.3.12
Oracle Oracle HTTP Server 9.0.3 .1
Oracle Oracle HTTP Server 9.0.2 .3
+ Oracle Oracle9i Application Server 9.0.2 .3
Oracle Oracle HTTP Server 9.0.2
Oracle Oracle HTTP Server 9.0.1
Oracle Oracle HTTP Server 8.1.7
Oracle Oracle HTTP Server 1.0.2 .2 Roll up 2
Oracle Oracle HTTP Server 1.0.2 .2
Oracle Oracle HTTP Server 1.0.2 .1
Oracle Oracle HTTP Server 1.0.2 .0
Oracle JInitiator 1.3.1
Oracle JInitiator 1.1.8
Oracle HTTP Server for Server 9.2
Oracle HTTP Server for Server 9.0.1
Oracle HTTP Server for Server 8.1.7
Oracle Forms And Reports 6.0.8 .25
Oracle Forms And Reports 4.5.10 .22
Oracle Express Server 6.3.4 .0
Oracle Enterprise Manager Grid Control 10g 10.1 .3
Oracle Enterprise Manager Grid Control 10g 10.1 .0.2
Oracle Enterprise Manager Database Control 10g 10.1 .0.4
Oracle Enterprise Manager Database Control 10g 10.1 .0.3
Oracle Enterprise Manager Database Control 10g 10.1 .0.2
Oracle Enterprise Manager Application Server Control 9.0.4 .1
Oracle Enterprise Manager Application Server Control 9.0.4 .0
HP Java SDK/RTE for HP-UX PA-RISC 1.4
HP Java SDK/RTE for HP-UX PA-RISC 1.3
+ HP HP-UX 11.20
+ HP HP-UX 11.11
+ HP HP-UX 11.0
+ HP HP-UX (VVOS) 11.0 4
HP HP-UX B.11.23
HP HP-UX B.11.22
HP HP-UX B.11.11
HP HP-UX B.11.00
Gentoo Linux
Apple Mac OS X Server 10.3.8
Apple Mac OS X Server 10.3.7
Apple Mac OS X Server 10.3.6
Apple Mac OS X Server 10.3.5
Apple Mac OS X Server 10.3.4
Apple Mac OS X 10.3.8
Apple Mac OS X 10.3.7
Apple Mac OS X 10.3.6
Apple Mac OS X 10.3.5
Apple Mac OS X 10.3.4
Not Vulnerable: Sun JRE (Windows Production Release) 1.4.2 _06
Sun JRE (Solaris Production Release) 1.4.2 _06
Sun JRE (Linux Production Release) 1.4.2 _06

Discussion

Sun Java Runtime Environment Java Plug-in JavaScript Security Restriction Bypass Vulnerability

A vulnerability is reported to exist in the access controls of the Java to JavaScript data exchange within web browsers that employ the Sun Java Plug-in. Reports indicate that it is possible for a malicious website that contains JavaScript code to exploit this vulnerability to load a dangerous Java class and to pass this class to an invoked applet.

** UPDATE: It is reported that the various methods of invoking Java applets can be abused to specify which version of a plug-in will be used to run an applet. If a vulnerable version is still installed on the computer, it may be possible for to specify that this version runs the applet instead of an updated version that is not prone to the vulnerability. Users affected by this vulnerability should remove earlier versions of the plug-in. This functionality could also be abused to prompt users to install vulnerable versions of the plug-in, so users should be wary of doing so. This general security weakness has been assigned an individual BID (11757). It is not known to what degree the Sun Java Runtime Environment Java Plug-in JavaScript Security Restriction Bypass Vulnerability is affected by this security weakness, though a number of other known vulnerabilities could be affected.

Exploit / POC

Sun Java Runtime Environment Java Plug-in JavaScript Security Restriction Bypass Vulnerability

The following example is available:

[script language=javascript]
var c=document.applets[0].getClass().forName('sun.text.Utility');
alert('got Class object: '+c)
[/script]

Solution / Fix

Sun Java Runtime Environment Java Plug-in JavaScript Security Restriction Bypass Vulnerability

Solution:
The vendor has released updates to address this issue. As an additional precaution, users should uninstall any previous vulnerable JVM installations to prevent attackers from specifying these versions be run instead of updated versions.

Apple has released an advisory (APPLE-SA-2005-02-22) and an update to address this vulnerability. Apple users are advised to see the referenced advisory for further information in regards to obtaining and applying an appropriate fix.

SuSE Linux has released a security summary report (SUSE-SR:2005:002) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.

Conectiva Linux has released advisory CLA-2004:900 along with fixes to address this issue. Please see the referenced advisory for further information.

Gentoo Linux has released advisory GLSA 200411-38 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
Sun JDK users:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-java/sun-jdk-1.4.2.06"
Sun JRE users:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-java/sun-jre-bin-1.4.2.06"
Blackdown JDK users:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-java/blackdown-jdk-1.4.2.01"
Blackdown JRE users:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-java/blackdown-jre-1.4.2.01"
Please see the referenced advisory for further information.

Sun has updated their initial advisory. The Java SDK packages have been added as vulnerable and resolutions have been provided.

HP has released an advisory HPSBUX01100 to address this issue in HP-UX. Please see the referenced advisory for more information.

Symantec has released advisory SYM05-001 to address this issue in various Symantec products. The affected products do not directly utilize the vulnerable application, but they contain a vulnerable version. This vulnerable version may be sent to the computer of administrators attempting to manage the devices, potentially exposing them to this vulnerability. Please see the referenced advisory for further information.

SuSE Linux has released a security summary report (SUSE-SR:2005:003) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.

Sun Microsystems has released Sun Alert ID: 57741 dealing with this issue in their Java Desktop System (JDS) packages for Linux. Sun has advised that patches are downloaded and implemented as soon as possible. To download and install the updated RPMs from the update servers, select the following sequence from the "launch" menu:

Launch >> Applications >> System Tools >> Online Update

Sun Microsystems has released Sun Alert ID: 101799 to address this issue on Sun Java Desktop System 2003. The issue has been addressed by RPM patch 118752-02, which may be applied by running the following command sequence from the "launch" menu:

Launch >> Applications >> System Tools >> Online Update

For more information on this issue and obtaining updates see the referenced Sun Microsystems advisories.

Oracle has released a Critical Patch Update (Critical Patch Update - July 2005) to address this issue. Currently, it is unknown which exact Oracle products include vulnerable packages. Information regarding obtaining and applying an appropriate patch can be found in the Oracle Critical Patch Update in references.

HP has released advisory HPSBUX01214 (SSRT051003 rev.0 - HP-UX Java Web Start remote unauthorized privileged access) to address this issue in HP-UX B.11.11 and HP-UX B.11.23. Please see the referenced advisory for more information.


Sun JRE (Windows Production Release) 1.3 .0_02

Sun JRE (Linux Production Release) 1.3 .0

HP Java SDK/RTE for HP-UX PA-RISC 1.3

Sun JRE (Solaris Production Release) 1.3 _04

Sun JRE (Linux Production Release) 1.3 .0_05

Sun JRE (Solaris Production Release) 1.3

Sun SDK (Linux Production Release) 1.3.1 _06

Sun JRE (Solaris Production Release) 1.3.1

Sun JRE (Solaris Production Release) 1.3.1 _02

Sun Java 2 Runtime Environment 1.3.1 _08

Sun SDK (Windows Production Release) 1.3.1 _05

Sun SDK (Solaris Production Release) 1.3.1 _01

Sun JRE (Solaris Production Release) 1.3.1 _03

Sun JRE (Solaris Production Release) 1.3.1 _09

Sun JRE (Solaris Production Release) 1.3.1 _05

Sun JRE (Linux Production Release) 1.3.1 _08

Sun JRE (Linux Production Release) 1.3.1 _01a

Sun SDK (Windows Production Release) 1.3.1 _07

Sun JRE (Linux Production Release) 1.3.1 _09

Sun JRE (Linux Production Release) 1.3.1 _01

Sun JRE (Windows Production Release) 1.3.1 _01a

Sun SDK (Solaris Production Release) 1.3.1 _06

Sun SDK (Windows Production Release) 1.3.1 _04

Sun SDK (Linux Production Release) 1.3.1 _07

Sun JRE (Windows Production Release) 1.3.1 _08

Sun JRE (Linux Production Release) 1.3.1 _05

Sun SDK (Solaris Production Release) 1.3.1 _05

Sun JRE (Linux Production Release) 1.3.1 _07

Sun JRE (Windows Production Release) 1.4

Sun JRE (Linux Production Release) 1.4

Sun JRE (Windows Production Release) 1.4 .0_01

Sun JRE (Linux Production Release) 1.4 .0_03

Sun SDK (Windows Production Release) 1.4

Sun SDK (Solaris Production Release) 1.4 .0_03

Sun SDK (Windows Production Release) 1.4 .0_4

Sun SDK (Windows Production Release) 1.4 .0_03

Sun JRE (Solaris Production Release) 1.4 .0_02

Sun JRE (Solaris Production Release) 1.4 .0_03

Sun SDK (Windows Production Release) 1.4 .0_01

Sun SDK (Solaris Production Release) 1.4 .0_02

Sun JRE (Solaris Production Release) 1.4.1 _02

Sun JRE (Solaris Production Release) 1.4.1

Sun SDK (Solaris Production Release) 1.4.1 _01

Sun JRE (Linux Production Release) 1.4.1 _03

Sun JRE (Windows Production Release) 1.4.1

Sun JRE (Solaris Production Release) 1.4.2

Sun SDK (Windows Production Release) 1.4.2 _05

Sun JRE (Solaris Production Release) 1.4.2 _05

Sun JRE (Linux Production Release) 1.4.2 _01

Sun SDK (Windows Production Release) 1.4.2

Sun Java 2 Runtime Environment 1.4.2

Sun JRE (Windows Production Release) 1.4.2 _03

Sun SDK (Linux Production Release) 1.4.2 _02

Sun JRE (Windows Production Release) 1.4.2 _01

Sun JRE (Windows Production Release) 1.4.2 _02

Sun JRE (Linux Production Release) 1.4.2 _03

Sun SDK (Windows Production Release) 1.4.2 _04

Sun SDK (Solaris Production Release) 1.4.2 _03

Sun JRE (Linux Production Release) 1.4.2 _04

Sun JRE (Windows Production Release) 1.4.2 _05

Sun SDK (Linux Production Release) 1.4.2 _04

Apple Mac OS X Server 10.3.4

Apple Mac OS X Server 10.3.6

Apple Mac OS X 10.3.8

Apple Mac OS X Server 10.3.8

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report