The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade icedtea-web. | Aug 30, 2017 | Aug 7, 2012 |
| Centos_linux | — | Upgrade icedtea-web-javadocUpgrade icedtea-web | Dec 1, 2016 | Aug 7, 2012 |
| Debian | — | Upgrade icedtea-web | Jul 30, 2024 | Aug 7, 2012 |
| Freebsd | — | Upgrade icedtea-web | Dec 10, 2025 | Aug 13, 2012 |
| Gentoo Linux | — | Upgrade dev-java/icedtea-bin. | Oct 30, 2017 | Aug 7, 2012 |
| Oracle_linux | — | Upgrade icedtea-webUpgrade icedtea-web-javadoc | Oct 16, 2024 | Aug 7, 2012 |
| Suse | — | Upgrade icedtea-webUpgrade java-1_8_0-openjdk-pluginUpgrade java-1_7_0-openjdk-plugin | Feb 17, 2015 | Jun 27, 2013 |
| Ubuntu | — | Upgrade icedtea-7-pluginUpgrade icedtea-6-plugin | Nov 8, 2024 | Aug 7, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub