CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Icedtea Web Project 1Icedtea Web Nov 21, 2024 Jul 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the appl...Show more |
3Debian Icedtea Web ProjectOpensuse3Debian Linux Icedtea WebLeapNov 21, 2024 Jul 31, 2019 N/A· v4 8.6 HIGH· v3 6.4 MEDIUM· v2 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This coul...Show more |
3Debian Icedtea Web ProjectOpensuse3Debian Linux Icedtea WebLeapNov 21, 2024 Jul 31, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a tr...Show more |
2Icedtea Web Project Redhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+3 moreNov 21, 2024 Jul 31, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to...Show more |