RSS   Vulnerabilities for 'Icedtea-web'   RSS

2022-07-07
 
CVE-2015-5236

CWE-345
 

 
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

 
2019-07-31
 
CVE-2019-10182

CWE-22
 

 
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

 


Copyright 2024, cxsecurity.com

 

Back to Top