CVE-2013-1926

Description

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.

Risk Information

Base Score
8.2
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS Score
Exploitation Probability
0.883

Associated Vulnerability

VulnerabilityOS Platform
A web browser plugin to execute Java applets (USN-1804-1) icedtea-netx_1.2.3-0ubuntu0.12.04.4_i386.debLinux
A web browser plugin to execute Java applets (USN-1804-1) icedtea-netx_1.2.3-0ubuntu0.12.04.4_amd64.debLinux
(RHSA-2013:0753) Moderate: icedtea-web security update icedtea-web-javadoc-1.2.3-2.el6_4.i686.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234