CVE-2015-5235: Fedoraproject Fedora

Medium severity, CVSS 4.3. EPSS: 3% chance of exploitation in the next 30 days.

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

Affected products

  • Fedoraproject Fedora: version 21 only; version 22 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Hpc Node: version 6 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat Icedtea: up to and including 1.5.2; version 1.6 only

Published 2015-10-09. Last modified 2026-06-17.