4.3

CVE-2015-5235

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 21
Fedoraproject ≫ Fedora Version 22
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Redhat ≫ Icedtea Version <= 1.5.2
Redhat ≫ Icedtea Version 1.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.03% 0.859
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.html
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167120.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167130.html
Third Party Advisory
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2015-September/033546.html
Patch
http://rhn.redhat.com/errata/RHSA-2016-0778.html
Third Party Advisory
http://www.securitytracker.com/id/1033780
http://www.ubuntu.com/usn/USN-2817-1
https://bugzilla.redhat.com/show_bug.cgi?id=1233697
Issue Tracking