7.5
CVSSv2

CVE-2012-3423

Published: 07/08/2012 Updated: 04/10/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The IcedTea-Web plugin prior to 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote malicious users to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat icedtea-web

redhat icedtea-web 1.1

redhat icedtea-web 1.0

Vendor Advisories

Synopsis Important: icedtea-web security update Type/Severity Security Advisory: Important Topic Updated icedtea-web packages that fix two security issues are now availablefor Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulne ...
The IcedTea-Web Java web browser plugin could be made to crash or possibly run programs as your login if it opened a specially crafted applet ...