CVE-2003-1572
Last modified
CVE-2003-1572 is a vulnerability of currently unknown severity. Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.. EPSS estimates a 1.72% chance of exploitation in the next 30 days.
Description
Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sun | Jmf | 2.1.1 |
| Sun | Jmf | 2.1.1a |
| Sun | Jmf | 2.1.1b |
| Sun | Jmf | 2.1.1c |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1572?
How severe is CVE-2003-1572?
How do I fix CVE-2003-1572?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-1566Microsoft Internet Information Services (IIS) 5.0 does not l…
- CVE-2003-1567The undocumented TRACK method in Microsoft Internet Informat…7.5
- CVE-2003-1568GoAhead WebServer before 2.1.6 allows remote attackers to ca…
- CVE-2003-1569GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME all…
- CVE-2003-1570The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x …
- CVE-2003-1571Web Wiz Guestbook 6.0 stores sensitive information under the…
- CVE-2003-1573The PointBase 4.6 database component in the J2EE 1.4 referen…
- CVE-2003-1574TikiWiki 1.6.1 allows remote attackers to bypass authenticat…
- CVE-2003-1575VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Ro…
- CVE-2003-1576Buffer overflow in pamverifier in Change Manager (CM) 1.0 fo…
- CVE-2003-1577Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 th…
- CVE-2003-1578Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 th…
Are you affected by CVE-2003-1572?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
