Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-3377

Опубликовано: 05 фев. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

РелизСтатусПримечание
devel

not-affected

1.2~pre1-0ubuntu1
hardy

DNE

lucid

not-affected

1.2-2ubuntu0.10.04.1
maverick

DNE

natty

released

1.1.1-0ubuntu1~11.04.2
oneiric

released

1.1.3-1ubuntu1.1
precise

not-affected

1.2~pre1-0ubuntu1
quantal

not-affected

1.2~pre1-0ubuntu1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

netx in icedtea-web
hardy

released

6b27-1.12.3-0ubuntu1~08.04.1
lucid

released

6b20-1.9.10-0ubuntu1~10.04.2
maverick

released

6b20-1.9.10-0ubuntu1~10.10.2
natty

not-affected

netx in icedtea-web
oneiric

not-affected

netx in icedtea-web
precise

not-affected

netx in icedtea-web
quantal

not-affected

netx in icedtea-web
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

released

6b18-1.8.10-0ubuntu1~10.04.2
maverick

released

6b18-1.8.10-0ubuntu1~10.10.2
natty

not-affected

netx in icedtea-web
oneiric

not-affected

netx in icedtea-web
precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

netx in icedtea-web
hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

not-affected

netx in icedtea-web
precise

not-affected

netx in icedtea-web
quantal

not-affected

netx in icedtea-web
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

not-affected

lucid

DNE

removed from archive
maverick

DNE

removed from archive
natty

DNE

removed from archive
oneiric

DNE

precise

DNE

quantal

DNE

upstream

not-affected

Показывать по

EPSS

Процентиль: 76%
0.00971
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 14 лет назад

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

nvd
больше 11 лет назад

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

debian
больше 11 лет назад

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x be ...

github
больше 3 лет назад

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

oracle-oval
почти 14 лет назад

ELSA-2011-1441: icedtea-web security update (MODERATE)

EPSS

Процентиль: 76%
0.00971
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2011-3377