CVE Vulnerabilities

CVE-2002-0866

Published: Oct 11, 2002 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka DLL Execution via JDBC Classes.

Affected Software

Name Vendor Start Version End Version
Virtual_machine Microsoft 2000 (including) 2000 (including)
Virtual_machine Microsoft 3000 (including) 3000 (including)
Virtual_machine Microsoft 3100 (including) 3100 (including)
Virtual_machine Microsoft 3188 (including) 3188 (including)
Virtual_machine Microsoft 3200 (including) 3200 (including)
Virtual_machine Microsoft 3300 (including) 3300 (including)
Virtual_machine Microsoft 3802 (including) 3802 (including)
Virtual_machine Microsoft 3805 (including) 3805 (including)

References