4.3
CVSSv2

CVE-2015-5235

Published: 09/10/2015 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

IcedTea-Web prior to 1.5.3 and 1.6.x prior to 1.6.1 does not properly determine the origin of unsigned applets, which allows remote malicious users to bypass the approval process or trick users into approving applet execution via a crafted web page.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 22

fedoraproject fedora 21

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux hpc node 6

opensuse opensuse 13.1

opensuse opensuse 13.2

redhat icedtea 1.6

redhat icedtea

Vendor Advisories

Several security issues were fixed in IcedTea Web ...
Debian Bug report logs - #798467 icedtea-web: CVE-2015-5234 CVE-2015-5235 Package: icedtea-web; Maintainer for icedtea-web is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 9 Sep 2015 17:45:06 UTC Severity: grave Tags: security Fou ...