296,843
Total vulnerabilities in the database
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
| Software | From | Fixed in | 
|---|---|---|
| icedtea-web_project / icedtea-web | - | 1.7.2.x | 
| icedtea-web_project / icedtea-web | 1.8.2 | 1.8.2.x | 
| redhat / enterprise_linux_desktop | 7.0 | 7.0.x | 
| redhat / enterprise_linux_workstation | 7.0 | 7.0.x | 
| redhat / enterprise_linux_server | 7.0 | 7.0.x | 
| redhat / enterprise_linux_server_eus | 7.6 | 7.6.x | 
| redhat / enterprise_linux_server_aus | 7.6 | 7.6.x |