CVE-2003-0896
Sun SDK/JRE 1.4.1_03 - Code Injection
Title source: llmDescription
The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Last Stage of Delirium · javadosmultiple
https://www.exploit-db.com/exploits/23276
References (8)
Scores
EPSS
0.2623
EPSS Percentile
96.2%
Classification
Status
draft
Affected Products (1)
sun/jre
< 1.4.1
Timeline
Published
Nov 17, 2003
Tracked Since
Feb 18, 2026