4.3
CVSSv2

CVE-2015-5235

Published: 09/10/2015 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

IcedTea-Web prior to 1.5.3 and 1.6.x prior to 1.6.1 does not properly determine the origin of unsigned applets, which allows remote malicious users to bypass the approval process or trick users into approving applet execution via a crafted web page.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 21

fedoraproject fedora 22

redhat enterprise linux server 6.0

redhat enterprise linux desktop 6.0

redhat enterprise linux hpc node 6

redhat enterprise linux workstation 6.0

opensuse opensuse 13.2

opensuse opensuse 13.1

redhat icedtea

redhat icedtea 1.6

Vendor Advisories

Debian Bug report logs - #798467 icedtea-web: CVE-2015-5234 CVE-2015-5235 Package: icedtea-web; Maintainer for icedtea-web is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 9 Sep 2015 17:45:06 UTC Severity: grave Tags: security Fou ...
Several security issues were fixed in IcedTea Web ...