Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
| Software | From | Fixed in |
|---|---|---|
| microsoft / windows_nt | 4.0-sp5 | 4.0-sp5.x |
| microsoft / windows_2000_terminal_services | - | - |
| microsoft / windows_xp | - | - |
| microsoft / windows_nt | 4.0-sp3 | 4.0-sp3.x |
| microsoft / windows_nt | 4.0-sp6a | 4.0-sp6a.x |
| microsoft / windows_2000 | - | - |
| microsoft / windows_nt | 4.0-sp6 | 4.0-sp6.x |
| microsoft / windows_nt | 4.0-sp1 | 4.0-sp1.x |
| microsoft / windows_nt | 4.0-sp4 | 4.0-sp4.x |
| microsoft / windows_98se | - | - |
| microsoft / windows_nt | 4.0-sp2 | 4.0-sp2.x |
| microsoft / windows_95 | - | - |
| microsoft / windows_me | - | - |
| microsoft / windows_98 | - | - |