Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2011-3377 at MITRE


The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)

SUSE information

SUSE Bugzilla entry: 729870 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.3
openSUSE 11.4
  • icedtea-web >= 1.1.4-0.2.1
  • icedtea-web-javadoc >= 1.1.4-0.2.1