4.3

CVE-2011-3377

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

Data is provided by the National Vulnerability Database (NVD)
RedhatIcedtea-web Version1.0
RedhatIcedtea-web Version1.0.1
RedhatIcedtea-web Version1.0.2
RedhatIcedtea-web Version1.0.3
RedhatIcedtea-web Version1.0.4
RedhatIcedtea-web Version1.0.5
RedhatIcedtea-web Version1.1
RedhatIcedtea-web Version1.1.1
RedhatIcedtea-web Version1.1.2
RedhatIcedtea-web Version1.1.3
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version10.10
CanonicalUbuntu Linux Version11.04
CanonicalUbuntu Linux Version11.10
OpensuseOpensuse Version12.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.97% 0.746
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N