Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Netscape Java Virtual Machine Insecure Call Vulnerability

A vulnerability has been reported in the Java Virtual Machine (JVM) implementation of Netscape 4 browsers. The vulnerability is due to some methods being called in an insecure way.

A remote attacker is able to create a specially crafted applet that exploits this vulnerability. Thus a carefully constructed applet may be able to load a malicious class into a JVM environment and escape any existing security constraints. This may be exploited by the attacker to run malicious code on the victim user's system.







 

Privacy Statement
Copyright 2009, SecurityFocus