Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rjx-hhcc-fqph

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.

The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.

EPSS

Процентиль: 19%
0.00059
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 12 лет назад

The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.

redhat
около 12 лет назад

The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.

nvd
почти 12 лет назад

The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.

debian
почти 12 лет назад

The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc ...

EPSS

Процентиль: 19%
0.00059
Низкий

Дефекты

CWE-200