CVE-2013-6493: Red Hat Icedtea-Web
Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.
Affected products
- Red Hat Icedtea-Web: up to and including 1.3.2; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; …
Published 2014-03-03. Last modified 2026-06-17.