CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
91.2%
Jiri Vanek discovered that IcedTea-Web would use the same classloader for
applets from different domains. A remote attacker could exploit this to
expose sensitive information or potentially manipulate applets from other
domains. (CVE-2013-1926)
It was discovered that IcedTea-Web did not properly verify JAR files and
was susceptible to the GIFAR attack. If a user were tricked into opening a
malicious website, a remote attacker could potentially exploit this to
execute code under certain circumstances. (CVE-2013-1927)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 12.10 | noarch | icedtea-netx | < 1.3.2-1ubuntu0.12.10.1 | UNKNOWN |
Ubuntu | 12.10 | noarch | icedtea-6-plugin | < 1.3.2-1ubuntu0.12.10.1 | UNKNOWN |
Ubuntu | 12.10 | noarch | icedtea-7-plugin | < 1.3.2-1ubuntu0.12.10.1 | UNKNOWN |
Ubuntu | 12.04 | noarch | icedtea-netx | < 1.2.3-0ubuntu0.12.04.1 | UNKNOWN |
Ubuntu | 12.04 | noarch | icedtea-6-plugin | < 1.2.3-0ubuntu0.12.04.1 | UNKNOWN |
Ubuntu | 12.04 | noarch | icedtea-7-plugin | < 1.2.3-0ubuntu0.12.04.1 | UNKNOWN |
Ubuntu | 11.10 | noarch | icedtea-netx | < 1.2.3-0ubuntu0.11.10.1 | UNKNOWN |
Ubuntu | 11.10 | noarch | icedtea-6-plugin | < 1.2.3-0ubuntu0.11.10.1 | UNKNOWN |
Ubuntu | 10.04 | noarch | icedtea-netx | < 1.2.3-0ubuntu0.10.04.1 | UNKNOWN |
Ubuntu | 10.04 | noarch | icedtea-6-plugin | < 1.2.3-0ubuntu0.10.04.1 | UNKNOWN |