CVE-2002-1291

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.

Scoring

CVSS base score
0.41
EPSS probability
10.29%
Published
2002-11-14
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs