2.1
CVSSv2

CVE-2013-6493

Published: 03/03/2014 Updated: 16/03/2014
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web prior to 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat icedtea-web 1.0.3

redhat icedtea-web 1.0.4

redhat icedtea-web 1.1.4

redhat icedtea-web 1.1.5

redhat icedtea-web 1.0.5

redhat icedtea-web 1.0.6

redhat icedtea-web 1.1.7

redhat icedtea-web 1.2

redhat icedtea-web

redhat icedtea-web 1.1

redhat icedtea-web 1.1.1

redhat icedtea-web 1.2.1

redhat icedtea-web 1.2.2

redhat icedtea-web 1.1.6

redhat icedtea-web 1.0.1

redhat icedtea-web 1.0.2

redhat icedtea-web 1.1.2

redhat icedtea-web 1.1.3

redhat icedtea-web 1.3

redhat icedtea-web 1.3.1

Vendor Advisories

IcedTea Web could be made to expose or alter sensitive information ...
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugincc in IcedTea-Web before 142 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp ...