Icedtea
5 CVEs tracked since 2019. Since Jul 2019, none of them reached CISA KEV.
Icedtea CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2019-07 | 3 | 0 |
| 2019-08 | null or fewer | |
| 2019-09 | null or fewer | |
| 2019-10 | 2 | 0 |
Products
The products that kept showing up in Icedtea's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Icedtea.
- CVE-2010-2783IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.9.1
- CVE-2010-2548IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.9.1
- CVE-2019-10181It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw...8.1
- CVE-2019-10182It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted applicatio...8.2
- CVE-2019-10185It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitra...8.6
The record
- Peak rank
- #144 in Jul 2019
- Busiest month shown
- Jul 2019, 3 CVEs
- Months with a KEV entry
- 0 since Jul 2019
- Monthly snapshots
- 2 since 2019