Логотип exploitDog
bind:"CVE-2015-5234" OR bind:"CVE-2015-5235"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2015-5234" OR bind:"CVE-2015-5235"

Количество 13

Количество 13

suse-cvrf логотип

SUSE-SU-2015:1689-1

почти 10 лет назад

Security update for icedtea-web

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1682-1

почти 10 лет назад

Security update for icedtea-web

EPSS: Низкий
oracle-oval логотип

ELSA-2016-0778

больше 9 лет назад

ELSA-2016-0778: icedtea-web security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2015-5235

почти 10 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-5235

около 10 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5235

почти 10 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5235

почти 10 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly dete ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5234

почти 10 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2015-5234

около 10 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5234

почти 10 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-5234

почти 10 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sani ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-vjh2-cm2h-354g

больше 3 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

EPSS: Низкий
github логотип

GHSA-c7wx-r8q7-fmcf

больше 3 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2015:1689-1

Security update for icedtea-web

почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:1682-1

Security update for icedtea-web

почти 10 лет назад
oracle-oval логотип
ELSA-2016-0778

ELSA-2016-0778: icedtea-web security, bug fix, and enhancement update (MODERATE)

больше 9 лет назад
ubuntu логотип
CVE-2015-5235

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

CVSS2: 4.3
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2015-5235

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

CVSS2: 4.3
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-5235

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

CVSS2: 4.3
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-5235

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly dete ...

CVSS2: 4.3
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-5234

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

CVSS2: 6.8
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2015-5234

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

CVSS2: 4.3
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-5234

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

CVSS2: 6.8
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-5234

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sani ...

CVSS2: 6.8
1%
Низкий
почти 10 лет назад
github логотип
GHSA-vjh2-cm2h-354g

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-c7wx-r8q7-fmcf

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу