VYPR
Unrated severityNVD Advisory· Published Apr 29, 2013· Updated Apr 29, 2026

CVE-2013-1926

CVE-2013-1926

Description

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.

Affected products

25
  • Red Hat/Icedtea Web20 versions
    cpe:2.3:a:redhat:icedtea-web:*:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:redhat:icedtea-web:*:*:*:*:*:*:*:*range: <=1.2.2
    • cpe:2.3:a:redhat:icedtea-web:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:icedtea-web:1.3.1:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

22

News mentions

0

No linked articles in our index yet.