CVE-2004-1029 describes a critical vulnerability in the Sun Java Plugin within Java 2 Runtime Environment (JRE) versions 1.4.2_01, 1.4.2_04, and potentially earlier. This flaw allows remote attackers to bypass security restrictions between JavaScript and Java applets, enabling the loading of unsafe classes and arbitrary code execution by leveraging the reflection API to access private Java packages. The vulnerability affects various products from vendors like Sun, HP, and Symantec, among others. Rated with a CVSS score of 9.3 (Critical), this vulnerability has a high severity due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. Its EPSS score of 0.370320000 indicates a higher-than-average exploitability probability compared to many other CVEs. While not listed on the CISA KEV catalog, exploit code for this vulnerability is publicly available, as evidenced by an ExploitDB entry. Despite the availability of exploit code, there is no indication of active exploitation in the wild, and community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:hp:java_sdk-rte:1.3:*:hp-ux_pa-risc:*:*:*:*:* | ||
1.4CPE matchmatch criteria | cpe:2.3:a:hp:java_sdk-rte:1.4:*:hp-ux_pa-risc:*:*:*:*:* | ||
1.3.1_01CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.3.1_01:*:linux:*:*:*:*:* | ||
1.3.1_01CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.3.1_01:*:solaris:*:*:*:*:* | ||
1.3.1_01aCPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.3.1_01a:*:windows:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.