Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IcedTea-Web 任意代码执行漏洞
Vulnerability Description
IcedTea-Web 1.2.1之前版本中存在漏洞。可被恶意人员利用操控应用程序使用插件。该漏洞源于处理没有NUL终止的字符串时存在内存破坏错误。攻击者可利用该漏洞通过包含恶意Java小应用程序的网页执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A