VYPR
Unrated severityNVD Advisory· Published Oct 9, 2015· Updated Jun 17, 2026

CVE-2015-5234

CVE-2015-5234

Description

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.