VDB

GCVE-110-MAGEIA-2015-376

GCVE-110-MAGEIA-2015-376
Advisory Published
Vulnetix · Advisory published September 17, 2015
Updated icedtea-web packages fix security vulnerabilities: It was discovered that IcedTea-Web did not properly sanitize applet URLs when storing applet trust settings. A malicious web page could use this flaw to inject trust-settings configuration, and cause applets to be executed without user approval (CVE-2015-5234). It was discovered that IcedTea-Web did not properly determine an applet's origin when asking the user if the applet should be run. A malicious page could use this flaw to cause IcedTea-Web to execute the applet without user approval, or confuse the user into approving applet execution based on an incorrectly indicated applet origin (CVE-2015-5235).

Affected Products

VendorProductVersionsPlatforms
Mageiaicedtea-web0 (affected), 1.5.3-1.mga5 (unaffected)

Browse GCVE Records

74,355 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›