5.8

CVE-2013-1926

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.

Data is provided by the National Vulnerability Database (NVD)
RedhatIcedtea-web Version <= 1.2.2
RedhatIcedtea-web Version1.0
RedhatIcedtea-web Version1.0.1
RedhatIcedtea-web Version1.0.2
RedhatIcedtea-web Version1.0.3
RedhatIcedtea-web Version1.0.4
RedhatIcedtea-web Version1.0.5
RedhatIcedtea-web Version1.0.6
RedhatIcedtea-web Version1.1
RedhatIcedtea-web Version1.1.1
RedhatIcedtea-web Version1.1.2
RedhatIcedtea-web Version1.1.3
RedhatIcedtea-web Version1.1.4
RedhatIcedtea-web Version1.1.5
RedhatIcedtea-web Version1.1.6
RedhatIcedtea-web Version1.1.7
RedhatIcedtea-web Version1.2
RedhatIcedtea-web Version1.2.1
RedhatIcedtea-web Version1.3
RedhatIcedtea-web Version1.3.1
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
OpensuseOpensuse Version12.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.7% 0.697
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N