« Volver al listado

CVE-2002-0865

Estado: ModificadaAlta (7.5)—

A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet, aka "Inappropriate Methods Exposed in XML Support Classes."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-0865",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": true,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-10-11T04:00:00.000",
  "references": [
    {
      "url": "http://www.iss.net/security_center/static/10135.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/140898",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/5752",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-052",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/10135.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/140898",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/5752",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-052",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet, aka \"Inappropriate Methods Exposed in XML Support Classes.\""
    },
    {
      "lang": "es",
      "value": "Una clase que soporta XML (Lenguaje de Marcas eXtensible) en Microsoft Virtual Machine (VM) 5.0.3805 y anteriores expone cierto métodos inseguros, que permiten a atacantes remotos ejecutar código inseguro mediante un applet de Java. También conocida como \"Métodos inapropiados expuestos en clases de soporte XML\""
    }
  ],
  "lastModified": "2026-06-16T21:58:17.547",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:virtual_machine:2000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A299BA2B-FD34-4FD5-8A4B-EA99DA9BA3EE"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:virtual_machine:3000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC2655D3-B360-4F82-B9CE-EECC95E0FAEE"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:virtual_machine:3100:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB67AEF8-DD02-4F20-B920-AC0B26D47C98"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:virtual_machine:3188:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B798772D-183C-4EE8-8E78-E37CCEC35B43"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:virtual_machine:3200:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D133B730-EEDA-46E7-8CC4-4D0104D65C11"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:virtual_machine:3300:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "962D0B64-8EEE-4589-84B3-D504906AEEC2"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:virtual_machine:3802:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB10F6CD-E12B-469B-8634-2185172D97D6"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:virtual_machine:3805:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBBEEAFB-9087-40C0-85A8-AAC82F6CD6D1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}