Back

CVE-2002-1295

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."

Published: Nov 29, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
microsoft java_virtual_machine 1.1

GitHub Security Advisory GHSA-xrw7-4wgq-5hg3

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 15.44%

Top 4% most likely to be exploited

Threat Score 34.6 / 100

Data Sources

NVD EPSS GitHub