The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade icedtea-web. | Aug 30, 2017 | Aug 7, 2012 |
| Centos_linux | — | Upgrade icedtea-webUpgrade icedtea-web-javadoc | Dec 1, 2016 | Aug 7, 2012 |
| Debian | — | Upgrade icedtea-web | Jul 30, 2024 | Aug 7, 2012 |
| Freebsd | — | Upgrade icedtea-web | Dec 10, 2025 | Aug 13, 2012 |
| Gentoo Linux | — | Upgrade dev-java/icedtea-bin. | Oct 30, 2017 | Aug 7, 2012 |
| Oracle_linux | — | Upgrade icedtea-web-javadocUpgrade icedtea-web | Oct 16, 2024 | Aug 7, 2012 |
| Suse | — | Upgrade java-1_7_0-openjdk-pluginUpgrade java-1_8_0-openjdk-pluginUpgrade icedtea-web | Feb 17, 2015 | Jun 27, 2013 |
| Ubuntu | — | Upgrade icedtea-7-pluginUpgrade icedtea-6-plugin | Nov 8, 2024 | Aug 7, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub