HIGH
Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka "XML sniffing."
Published Jun 2, 2009
10.0
HIGHCVSS 2.0
EPSS 2.36%
Description
Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka "XML sniffing."
Affected products
No data.
OR
- 1.4.0
- 1.4.0_01
- 1.4.0_01
- 1.4.0_01
- 1.4.0_01
- 1.4.0_02
- 1.4.0_02
- 1.4.0_02
- 1.4.0_02
- 1.4.0_03
- 1.4.0_03
- 1.4.0_03
- 1.4.0_03
- 1.4.0_04
- 1.4.0_04
- 1.4.0_04
- 1.4.0_04
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1
- 1.4.1_01
- 1.4.1_01
- 1.4.1_01
- 1.4.1_01
- 1.4.1_02
- 1.4.1_02
- 1.4.1_02
- 1.4.1_02
- 1.4.1_03
- 1.4.1_03
- 1.4.1_03
- 1.4.1_03
- 1.4.1_04
- 1.4.1_04
- 1.4.1_04
- 1.4.1_04
- 1.4.1_05
- 1.4.1_05
- 1.4.1_05
- 1.4.1_05
- 1.4.1_06
- 1.4.1_06
- 1.4.1_06
- 1.4.1_06
- 1.4.1_07
- 1.4.1_07
- 1.4.1_07
- 1.4.1_07
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2
- 1.4.2_01
- 1.4.2_1
- 1.4.2_2
- 1.4.2_02
- 1.4.2_03
- 1.4.2_3
- 1.4.2_4
- 1.4.2_04
- 1.4.2_5
- 1.4.2_6
- 1.4.2_7
- 1.4.2_8
- 1.4.2_9
- 1.4.2_10
- 1.4.2_11
- 1.4.2_12
- 1.4.2_13
- 1.4.2_14
- 1.4.2_15
- 1.4.2_21
- 1.4.0
- 1.4.0_01
- 1.4.0_02
- 1.4.0_03
- 1.4.0_04
- 1.4.1
- 1.4.1_01
- 1.4.1_02
- 1.4.1_03
- 1.4.1_04
- 1.4.1_05
- 1.4.1_06
- 1.4.1_07
- 1.4.2
- 1.4.2_01
- 1.4.2_02
- 1.4.2_03
- 1.4.2_04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://archive.cert.uni-stuttgart.de/uniras/2004/08/msg00007.html vendor-advisoryx_refsource_SUNALERT
- http://groups.google.com/group/comp.security.unix/tree/browse_frm/month/2004-10/fe63f1daa9689d50?rnum=161&_done=%2Fgroup%2Fcomp.security.unix%2Fbrowse_frm%2Fmonth%2F2004-10%3Ffwc%3D1%26#doc_29036353582c690d vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/12206 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1011661 vdb-entryx_refsource_SECTRACK
- http://www.osvdb.org/8288 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/371208 mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/10844 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-2754 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16864 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://archive.cert.uni-stuttgart.de/uniras/2004/08/msg00007.html | vendor-advisoryx_refsource_SUNALERT | |
| http://groups.google.com/group/comp.security.unix/tree/browse_frm/month/2004-10/fe63f1daa9689d50?rnum=161&_done=%2Fgroup%2Fcomp.security.unix%2Fbrowse_frm%2Fmonth%2F2004-10%3Ffwc%3D1%26#doc_29036353582c690d | vendor-advisoryx_refsource_HP | |
| http://secunia.com/advisories/12206 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securitytracker.com/id?1011661 | vdb-entryx_refsource_SECTRACK | |
| http://www.osvdb.org/8288 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/archive/1/371208 | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/10844 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-2754 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/16864 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2009
Updated Aug 8, 2024
Reserved Jun 1, 2009
Link CVE-2004-2764
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2004-2754 Assigner mitre
Published Jun 2, 2009
Updated Aug 8, 2024
Exploited since n/a
Link EUVD-2004-2754