Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-10182
Description:It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
Test IDs: 1.3.6.1.4.1.25623.1.0.891914  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-10182
20191007 CVE-2019-10181, CVE-2019-10182, CVE-2019-10185: IcedTea-Web vulnerabilities leading to RCE
https://seclists.org/bugtraq/2019/Oct/5
[debian-lts-announce] 20190909 [SECURITY] [DLA 1914-1] icedtea-web security update
https://lists.debian.org/debian-lts-announce/2019/09/msg00008.html
http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html
http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10182
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10182
https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327
https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327
https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344
https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344
openSUSE-SU-2019:1911
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.html




© 1998-2025 E-Soft Inc. All rights reserved.