CVE-2013-1926

8 documents8 sources
Severity
5.8MEDIUM
EPSS
0.9%
top 24.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 29
Latest updateMay 14

Description

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages3 packages

Debianicedtea-web< 1.3.2-1+3
NVDredhat/icedtea-web1.2.2+19

Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10

🔴Vulnerability Details

3
GHSA
GHSA-vwgw-5wg9-mw8j: The IcedTea-Web plugin before 12022-05-14
OSV
CVE-2013-1926: The IcedTea-Web plugin before 12013-04-29
CVEList
CVE-2013-1926: The IcedTea-Web plugin before 12013-04-29

📋Vendor Advisories

3
Ubuntu
IcedTea-Web vulnerabilities2013-04-18
Red Hat
icedtea-web: class loader sharing for applets with same codebase paths2013-04-17
Debian
CVE-2013-1926: icedtea-web - The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class l...2013

💬Community

1
Bugzilla
CVE-2013-1926 icedtea-web: class loader sharing for applets with same codebase paths2013-02-28
CVE-2013-1926 (MEDIUM CVSS 5.8) | The IcedTea-Web plugin before 1.2.3 | cvebase.io