IcedTea Web is a Java Web Start implementation that enables execution of Java applications delivered via JNLP, occupying a narrow but strategically important role in legacy Java deployment infrastructure. The vendor's vulnerability footprint concentrates in this single implementation product and reflects the complexity inherent to parsing untrusted manifests and managing sandboxed application execution. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icedtea Web Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10185HIGH It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write | Jul 31, 2019 | 8.6 | 29 | NO | NO |
CVE-2019-10181HIGH It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker co | Jul 31, 2019 | 8.1 | 26 | NO | NO |
CVE-2019-10182MEDIUM It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially c | Jul 31, 2019 | 6.5 | 23 | NO | NO |
CVE-2015-5236HIGH It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified | Jul 7, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icedtea Web Project.
Media articles that mention a CVE ID that affects a product developed by Icedtea Web Project — matched by CVE ID, not by vendor name.