Icedtea

Vendor:

First CVE: Dec 8, 2010 · Active for 15 years

9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Icedtea over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 8, 2010
15 years ago
Most Recent CVE
Apr 24, 2017
3,380 days ago

CVE Severity & Scoring

Icedtea9 CVEs
All CVEs352,719 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (44.4%)
Unknown5 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High4 (44.4%)
Unknown5 (55.6%)
User Interaction
None2 (22.2%)
Unknown5 (55.6%)
Required2 (22.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (44.4%)
Unknown5 (55.6%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entitie
Feb 4, 20116.824NONO
The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwi
Jan 20, 20116.823NONO
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u131 and 8u121. Difficult to exploit vulnerability
Apr 24, 20178.321NONO
IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obt
Dec 8, 20105.021NONO
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8
Apr 24, 20173.718NONO
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration
Oct 9, 20156.818NONO
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java
Apr 24, 20173.115NONO
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick us
Oct 9, 20154.315NONO
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8
Apr 24, 20173.714NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Icedtea

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.416.82.6%00
1.9.326.82.6%00
1.9.226.82.6%00
1.9.126.82.6%00
1.936.22.7%00
1.8.416.82.6%00
1.8.326.82.6%00
1.8.236.22.7%00
1.8.136.22.7%00
1.836.22.7%00
1.7.716.82.6%00
1.7.626.82.6%00
1.7.526.82.6%00
1.7.426.82.6%00
1.7.326.82.6%00
1.7.226.82.6%00
1.7.126.82.6%00
1.736.22.7%00
1.635.42.7%00
1.515.03.0%00