The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2013-04-29T22:00:00

Updated: 2017-08-28T12:57:01

Reserved: 2013-02-19T00:00:00


Link: CVE-2013-1926

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2013-04-29T22:55:08.297

Modified: 2018-10-30T16:27:33.937


Link: CVE-2013-1926

JSON object: View

cve-icon Redhat Information

No data.