CVE-2011-0706 describes a privilege escalation vulnerability in the JNLPClassLoader class of IcedTea-Web before version 1.0.1, affecting OpenJDK Runtime Environment 1.6.0, Red Hat IcedTea-Web, Red Hat JDK, Sun IcedTea-Web, and Sun JDK. The vulnerability, stemming from "inappropriate security descriptor" assignment with multiple signers, allows remote attackers to gain privileges through unknown vectors. With a CVSS score of 7.5 (High), it presents a low attack complexity and no authentication requirement, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:redhat:icedtea-web:1.0:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:redhat:icedtea-web:1.0:pre:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:redhat:icedtea-web:1.0.1:pre:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.