CVE-2002-0076 - CVE House
Back to Database
Status published High CVE-2002-0076

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to...

Vulnerability Description

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-0076

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

java jre-jdk, virtual machine, jdk, jre, sdk
Vulnerable Versions:
1.1.8, 1.2.2, 1.3, 3802, 1.3.0, 1.3.1, 1.2.2_10, 1.2.2_010, 1.3.1_01, 1.3.1_01a, 1.3_05

Timeline

Official Publish: April 2nd, 2003
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.