Back

CVE-2002-0076

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.

Published: Mar 19, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (17)

Vendor Product Version
hp java_jre-jdk 1.1.8
hp java_jre-jdk 1.2.2
hp java_jre-jdk 1.3
microsoft virtual_machine 3802
sun jdk 1.1.8
sun jdk 1.1.8
sun jre 1.1.8
sun jre 1.1.8
sun jre 1.2.2
sun jre 1.3.0
sun jre 1.3.1
sun jre 1.3.1
sun sdk 1.2.2_10
sun sdk 1.2.2_010
sun sdk 1.3.1_01
sun sdk 1.3.1_01a
sun sdk 1.3_05

GitHub Security Advisory GHSA-x79p-2mvq-597f

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 26.86%

Top 2% most likely to be exploited

Threat Score 38.1 / 100

Data Sources

NVD EPSS GitHub