← Vulnerability feed

Vulnerability record · CVE-2004-1029 · published 1 March 2005

CVE-2004-1029: Hp java sdk-rte permissions and access controls vulnerability

Hp · Java Sdk Rte

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

9.3 CVSS 2.0 High EPSS 17% · top 3.0% CWE-264 · Permissions and access controls
9.3CVSS 2.0 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
30References
16 Jun 2026Last modified by NVD

Description

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://jouko.iki.fi/adv/javaplugin.html
http://lists.apple.com/archives/security-announce/2005/Feb/msg00000.html
http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html
http://secunia.com/advisories/13271 Vendor Advisory
http://secunia.com/advisories/29035 Vendor Advisory
http://securityreason.com/securityalert/61
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1 PatchVendor Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1 PatchVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg21257249
http://www.idefense.com/application/poi/display?id=158&type=vulnerabilities
http://www.kb.cert.org/vuls/id/760344 US Government Resource
http://www.securityfocus.com/bid/12317 Patch
http://www.vupen.com/english/advisories/2008/0599 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/18188
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5674
http://jouko.iki.fi/adv/javaplugin.html
http://lists.apple.com/archives/security-announce/2005/Feb/msg00000.html
http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html
http://secunia.com/advisories/13271 Vendor Advisory
http://secunia.com/advisories/29035 Vendor Advisory
http://securityreason.com/securityalert/61
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1 PatchVendor Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1 PatchVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg21257249
http://www.idefense.com/application/poi/display?id=158&type=vulnerabilities
http://www.kb.cert.org/vuls/id/760344 US Government Resource
http://www.securityfocus.com/bid/12317 Patch
http://www.vupen.com/english/advisories/2008/0599 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/18188
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5674

Track CVE-2004-1029 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed10.0CVE-2013-5809Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 5.9%10.0CVE-2013-5814Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5817Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5824Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%10.0CVE-2013-5782Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRoc…EPSS 6.3%10.0CVE-2013-5787Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%10.0CVE-2013-5789Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2004-1029), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.