6.8
CVSSv2

CVE-2012-3422

Published: 07/08/2012 Updated: 04/10/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The getFirstInTableInstance function in the IcedTea-Web plugin prior to 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat icedtea-web

redhat icedtea-web 1.1

redhat icedtea-web 1.0

Vendor Advisories

Synopsis Important: icedtea-web security update Type/Severity Security Advisory: Important Topic Updated icedtea-web packages that fix two security issues are now availablefor Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulne ...
The IcedTea-Web Java web browser plugin could be made to crash or possibly run programs as your login if it opened a specially crafted applet ...