CVE-2013-1926: Canonical Ubuntu Linux
Medium severity, CVSS 5.8. EPSS: 1.9% chance of exploitation in the next 30 days.
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 11.10 only; version 12.04 only; version 12.10 only
- Opensuse Opensuse: version 12.2 only
- Red Hat Icedtea-Web: up to and including 1.2.2; version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; …
Published 2013-04-29. Last modified 2026-06-16.