ID

VAR-200112-0219


CVE

CVE-2001-1480


TITLE

Sun JRE/SDK Clipboard popup vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200112-198

DESCRIPTION

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard. In the default java security model for applets, this access should not be granted

Trust: 1.26

sources: NVD: CVE-2001-1480 // BID: 3441 // VULHUB: VHN-4284

AFFECTED PRODUCTS

vendor:sunmodel:jdkscope:eqversion:1.2.2_07

Trust: 1.6

vendor:sunmodel:jdkscope:eqversion:1.2.2_07a

Trust: 1.6

vendor:sunmodel:jdkscope:eqversion:1.3.0_02

Trust: 1.6

vendor:sunmodel:sdkscope:eqversion:1.1.3

Trust: 1.3

vendor:sunmodel:sdkscope:eqversion:1.3.0

Trust: 1.3

vendor:sunmodel:jrescope:eqversion:1.3.0

Trust: 1.3

vendor:sunmodel:jrescope:eqversion:1.2.2

Trust: 1.3

vendor:sunmodel:jrescope:eqversion:1.2.2_003

Trust: 1.0

vendor:sunmodel:jrescope:eqversion:1.2.2_004

Trust: 1.0

vendor:sunmodel:jrescope:eqversion:1.2.2_007

Trust: 1.0

vendor:applemodel:mac os runtime for javascope:eqversion:2.2.4

Trust: 1.0

vendor:sunmodel:jrescope:eqversion:1.2.2_07

Trust: 1.0

vendor:sunmodel:jrescope:eqversion:1.2.2_006

Trust: 1.0

vendor:sunmodel:jrescope:eqversion:1.2.2_005

Trust: 1.0

vendor:sunmodel:sdk .0 02scope:eqversion:1.3

Trust: 0.9

vendor:sunmodel:sdk 007scope:eqversion:1.2.2

Trust: 0.9

vendor:sunmodel:jre .0 02scope:eqversion:1.3

Trust: 0.9

vendor:sunmodel:jre 007scope:eqversion:1.2.2

Trust: 0.9

vendor:sunmodel:sdk 07ascope:eqversion:1.2.2

Trust: 0.3

vendor:sunmodel:sdk 07scope:eqversion:1.2.2

Trust: 0.3

vendor:sunmodel:jre 07scope:eqversion:1.2.2

Trust: 0.3

vendor:sunmodel:jre .0 01scope:eqversion:1.3

Trust: 0.3

vendor:sunmodel:jre 006scope:eqversion:1.2.2

Trust: 0.3

vendor:sunmodel:jre 005scope:eqversion:1.2.2

Trust: 0.3

vendor:sunmodel:jre 004scope:eqversion:1.2.2

Trust: 0.3

vendor:sunmodel:jre 003scope:eqversion:1.2.2

Trust: 0.3

vendor:applemodel:macintosh runtime for javascope:eqversion:2.2.4

Trust: 0.3

vendor:applemodel:macintosh runtime for javascope:neversion:2.2.5

Trust: 0.3

vendor:applemodel:mac osscope:neversion:x10.1

Trust: 0.3

sources: BID: 3441 // CNNVD: CNNVD-200112-198 // NVD: CVE-2001-1480

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-1480
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200112-198
value: HIGH

Trust: 0.6

VULHUB: VHN-4284
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2001-1480
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-4284
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-4284 // CNNVD: CNNVD-200112-198 // NVD: CVE-2001-1480

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2001-1480

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200112-198

TYPE

access verification error

Trust: 0.6

sources: CNNVD: CNNVD-200112-198

EXTERNAL IDS

db:BIDid:3441

Trust: 2.0

db:NVDid:CVE-2001-1480

Trust: 1.7

db:XFid:7333

Trust: 0.6

db:HPid:HPSBUX0110-174

Trust: 0.6

db:BUGTRAQid:20011017 MAC OS X V10.0.X J2SE V1.3 CLIPBOARD TAPPING VULNERABILITY

Trust: 0.6

db:CNNVDid:CNNVD-200112-198

Trust: 0.6

db:VULHUBid:VHN-4284

Trust: 0.1

sources: VULHUB: VHN-4284 // BID: 3441 // CNNVD: CNNVD-200112-198 // NVD: CVE-2001-1480

REFERENCES

url:http://www.securityfocus.com/bid/3441

Trust: 1.7

url:http://cert.uni-stuttgart.de/archive/bugtraq/2001/10/msg00120.html

Trust: 1.7

url:http://www.securityfocus.com/advisories/3617

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/7333

Trust: 1.1

url:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/208&type=0&nav=sec.sba

Trust: 1.0

url:http://xforce.iss.net/xforce/xfdb/7333

Trust: 0.6

url:http://www.apple.com/support/security/security_updates.html

Trust: 0.3

url:http://lists.apple.com/archives/java-dev/2001/feb/9.html

Trust: 0.3

url:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/208&type=0&nav=sec.sba

Trust: 0.1

sources: VULHUB: VHN-4284 // BID: 3441 // CNNVD: CNNVD-200112-198 // NVD: CVE-2001-1480

CREDITS

Reported to java-dev@lists.apple.com mailing list by Cameron McNeil on Feburary 9, 2001.

Trust: 0.9

sources: BID: 3441 // CNNVD: CNNVD-200112-198

SOURCES

db:VULHUBid:VHN-4284
db:BIDid:3441
db:CNNVDid:CNNVD-200112-198
db:NVDid:CVE-2001-1480

LAST UPDATE DATE

2024-08-14T14:16:21.003000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-4284date:2017-07-11T00:00:00
db:BIDid:3441date:2001-02-09T00:00:00
db:CNNVDid:CNNVD-200112-198date:2005-10-20T00:00:00
db:NVDid:CVE-2001-1480date:2017-07-11T01:29:09.540

SOURCES RELEASE DATE

db:VULHUBid:VHN-4284date:2001-12-31T00:00:00
db:BIDid:3441date:2001-02-09T00:00:00
db:CNNVDid:CNNVD-200112-198date:2001-12-31T00:00:00
db:NVDid:CVE-2001-1480date:2001-12-31T05:00:00