Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11177
Category:Windows : Microsoft Bulletins
Title:Microsoft VM Multiple Vulnerabilities (MS02-052, MS02-069)
Summary:Microsoft Virtual Machine (Microsoft VM) is prone to multiple; vulnerabilities.
Description:Summary:
Microsoft Virtual Machine (Microsoft VM) is prone to multiple
vulnerabilities.

Vulnerability Insight:
Without the patch applied from MS02-052 the following flaws
exist:

- CVE-2002-0866: DLL execution via JDBC classes

- CVE-2002-0867: Handle validation flaw

- CVE-2002-0865: Inappropriate methods exposed in XML support classes

Without the patch applied from MS02-069 the following flaws exist:

- CVE-2002-1257: COM Object Access Vulnerability

- CVE-2002-1258: CODEBASE Spoofing Vulnerabilities

- CVE-2002-1259: Domain Spoofing Vulnerability

- CVE-2002-1260: JDBC API Vulnerability

- CVE-2002-1261: Standard Security Manager Access Vulnerability

- CVE-2002-1325: User.dir Exposure Vulnerability

- CVE-2002-1263: Incomplete Java object Instantiation Vulnerability

- CVE-2002-1292: Package Access Restriction Bypassing Vulnerability

- CVE-2002-1295: HTML Applet Tag Class Restriction Bypass Vulnerability

Affected Software/OS:
All builds of the Microsoft VM up to and including build
5.0.3805 are affected by these vulnerabilities.

Solution:
The vendor has releases updates. Please see the references for
more information.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-0866
BugTraq ID: 5751
http://www.securityfocus.com/bid/5751
Bugtraq: 20020923 Technical information about the vulnerabilities fixed by MS-02-52 (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2002-09/0271.html
CERT/CC vulnerability note: VU#307306
http://www.kb.cert.org/vuls/id/307306
Microsoft Security Bulletin: MS02-052
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-052
http://www.iss.net/security_center/static/10133.php
Common Vulnerability Exposure (CVE) ID: CVE-2002-0867
BugTraq ID: 5750
http://www.securityfocus.com/bid/5750
CERT/CC vulnerability note: VU#792881
http://www.kb.cert.org/vuls/id/792881
http://www.iss.net/security_center/static/10134.php
Common Vulnerability Exposure (CVE) ID: CVE-2002-0865
BugTraq ID: 5752
http://www.securityfocus.com/bid/5752
CERT/CC vulnerability note: VU#140898
http://www.kb.cert.org/vuls/id/140898
http://www.iss.net/security_center/static/10135.php
Common Vulnerability Exposure (CVE) ID: CVE-2002-1257
BugTraq ID: 6371
http://www.securityfocus.com/bid/6371
Microsoft Security Bulletin: MS02-069
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-069
Common Vulnerability Exposure (CVE) ID: CVE-2002-1258
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A582
Common Vulnerability Exposure (CVE) ID: CVE-2002-1259
Common Vulnerability Exposure (CVE) ID: CVE-2002-1260
BugTraq ID: 6379
http://www.securityfocus.com/bid/6379
Computer Incident Advisory Center Bulletin: N-026
http://www.ciac.org/ciac/bulletins/n-026.shtml
XForce ISS Database: msvm-jdbc-gain-access(10833)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10833
Common Vulnerability Exposure (CVE) ID: CVE-2002-1261
Common Vulnerability Exposure (CVE) ID: CVE-2002-1325
BugTraq ID: 6380
http://www.securityfocus.com/bid/6380
Common Vulnerability Exposure (CVE) ID: CVE-2002-1263
Common Vulnerability Exposure (CVE) ID: CVE-2002-1292
BugTraq ID: 6133
http://www.securityfocus.com/bid/6133
Bugtraq: 20021108 Technical information about unpatched MS Java vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=103682630823080&w=2
CERT/CC vulnerability note: VU#237777
http://www.kb.cert.org/vuls/id/237777
http://marc.info/?l=ntbugtraq&m=103684360031565&w=2
XForce ISS Database: msvm-ssm-restriction-bypass(10585)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10585
Common Vulnerability Exposure (CVE) ID: CVE-2002-1295
BugTraq ID: 6136
http://www.securityfocus.com/bid/6136
http://www.iss.net/security_center/static/10588.php
CopyrightCopyright (C) 2002 SECNAP Network Security, LLC

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.