BlackKite: Home
Menu

PUBLISHED DATE: March 19, 2002CVE-2002-0076:
Java Runtime Environment (JRE)...

CVSS:
7.5
EPSS:
114.40%
Exploitability:
10
In KEV:
No
Description

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.

Products
Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2002-0076, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2002-0076 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?