Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqp6-h2hr-w9xj

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

EPSS

Процентиль: 76%
0.00971
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

redhat
почти 14 лет назад

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

nvd
больше 11 лет назад

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

debian
больше 11 лет назад

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x be ...

oracle-oval
почти 14 лет назад

ELSA-2011-1441: icedtea-web security update (MODERATE)

EPSS

Процентиль: 76%
0.00971
Низкий