Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-0025
Description:IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.
Test IDs: 1.3.6.1.4.1.25623.1.0.69567  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-0025
43135
http://secunia.com/advisories/43135
46110
http://www.securityfocus.com/bid/46110
DSA-2224
http://www.debian.org/security/2011/dsa-2224
GLSA-201406-32
http://security.gentoo.org/glsa/glsa-201406-32.xml
MDVSA-2011:054
http://www.mandriva.com/security/advisories?name=MDVSA-2011:054
USN-1055-1
http://www.ubuntu.com/usn/USN-1055-1
http://blog.fuseyism.com/index.php/2011/02/01/security-icedtea6-178-185-195-released/
http://blog.fuseyism.com/index.php/2011/02/01/security-icedtea6-178-185-195-released/
http://icedtea.classpath.org/hg/release/icedtea-web-1.0?cmd=changeset%3Bnode=3bd328e4b515
http://icedtea.classpath.org/hg/release/icedtea-web-1.0?cmd=changeset%3Bnode=3bd328e4b515
icedtea-jar-security-bypass(65151)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65151




© 1998-2025 E-Soft Inc. All rights reserved.