Количество 11
Количество 11
CVE-2019-10185
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
CVE-2019-10185
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
CVE-2019-10185
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
CVE-2019-10185
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was ...
GHSA-3q3x-68j9-f9vv
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
BDU:2019-02868
Уязвимость плагина IcedTea-Web, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записать произвольные файлы в файловую систему устройства
openSUSE-SU-2019:1911-1
Security update for icedtea-web
SUSE-SU-2022:1259-1
Security update for icedtea-web
SUSE-SU-2019:2033-1
Security update for icedtea-web
ELSA-2019-2004
ELSA-2019-2004: icedtea-web security update (IMPORTANT)
ELSA-2019-2003
ELSA-2019-2003: icedtea-web security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-10185 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox. | CVSS3: 8.6 | 4% Низкий | около 7 лет назад | |
CVE-2019-10185 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox. | CVSS3: 8.2 | 4% Низкий | около 7 лет назад | |
CVE-2019-10185 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox. | CVSS3: 8.6 | 4% Низкий | около 7 лет назад | |
CVE-2019-10185 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was ... | CVSS3: 8.6 | 4% Низкий | около 7 лет назад | |
GHSA-3q3x-68j9-f9vv It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox. | CVSS3: 8.6 | 4% Низкий | около 4 лет назад | |
BDU:2019-02868 Уязвимость плагина IcedTea-Web, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записать произвольные файлы в файловую систему устройства | CVSS3: 8.6 | 4% Низкий | около 7 лет назад | |
openSUSE-SU-2019:1911-1 Security update for icedtea-web | почти 7 лет назад | |||
SUSE-SU-2022:1259-1 Security update for icedtea-web | больше 4 лет назад | |||
SUSE-SU-2019:2033-1 Security update for icedtea-web | около 7 лет назад | |||
ELSA-2019-2004 ELSA-2019-2004: icedtea-web security update (IMPORTANT) | около 7 лет назад | |||
ELSA-2019-2003 ELSA-2019-2003: icedtea-web security update (IMPORTANT) | около 7 лет назад |
Уязвимостей на страницу