Sploitus

CVE-2003-0896

1 known exploit for CVE-2003-0896

The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.

Affected products
Jre, Java Virtual Machine, Sun Sdk
Sun Jre
≤ 1.4.1
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
14.0% (96th percentile)
NVD status
Modified
Published
2003-10-25
CVE-2003-0896 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2003-0896

Proof-of-concept code and exploit modules indexed by Sploitus