IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2015-10-09T14:00:00

Updated: 2016-12-06T18:57:01

Reserved: 2015-07-01T00:00:00


Link: CVE-2015-5235

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-10-09T14:59:05.670

Modified: 2018-10-30T16:27:35.843


Link: CVE-2015-5235

JSON object: View

cve-icon Redhat Information

No data.

CWE