Adobe PhotoDeluxe Java Execution Vulnerability

BID:4106

Info

Adobe PhotoDeluxe Java Execution Vulnerability

Bugtraq ID: 4106
Class: Design Error
CVE: CVE-2002-1601
Remote: Yes
Local: No
Published: Feb 09 2002 12:00AM
Updated: Jul 11 2009 10:56AM
Credit: Dr. Hiromitsu Takagi is credited with discovering this issue.
Vulnerable: Adobe PhotoDeluxe 4.0
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
Adobe PhotoDeluxe 3.1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
Adobe PhotoDeluxe 3.0
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
Not Vulnerable:

Discussion

Adobe PhotoDeluxe Java Execution Vulnerability

Adobe PhotoDeluxe is image editing/photo album software that ships with a number of imaging devices. It runs on Microsoft Windows 9x/ME/NT/2000/XP operating systems.

Adobe PhotoDeluxe installs sensitive Java code in a public location.

One of Adobe PhotoDeluxe's features is to allow users to download extra design elements from the Adobe website. The functionality is called "Connectables" and is accomplished via the installation of Java code on the user's system. However, the Java applet is installed in an insecure manner, which may be exploited by malicious webpages or HTML e-mail viewed through the Internet Explorer web browser.

This may grant unauthorized access to sensitive information on an affected user's system. This problem, in some cases, may also result in the execution of arbitrary code.

Versions of Adobe PhotoDeluxe also exist for MacOS, though it is not known whether they are affected by this issue.

References

Adobe PhotoDeluxe Java Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report