Icedtea-web Project
Icedtea-web Project Icedtea-web: vulnerabilidades y CVE
Icedtea-web Project Icedtea-web tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-5236 | Alta (7.5) | 0.83% | — | 7 jul 2022 | It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the… |
| CVE-2019-10185 | Alta (8.6) | 4.0% | — | 31 jul 2019 | It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This… |
| CVE-2019-10181 | Alta (8.1) | 1.2% | — | 31 jul 2019 | It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a… |
| CVE-2019-10182 | Media (6.5) | 2.7% | — | 31 jul 2019 | It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to… |