IcedTea-Web: second-level domain subdomains and suffix domain SOP bypass
Published Feb 5, 2014
4.3
MEDIUMCVSS 2.0
EPSS 2.22%
Description
The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.
Affected products
No data.
Configuration 1
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
Configuration 2
- 10.04
- 10.10
- 11.04
- 11.10
- 12.1
No data.
Red Hat Enterprise Linux 6
icedtea-web-0:1.0.6-1.el6_1
Fixed · RHSA-2011:1441
Red Hat Enterprise Linux 5
java-1.6.0-openjdk
Not affected
Red Hat Enterprise Linux 6
java-1.6.0-openjdk
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | icedtea-web-0:1.0.6-1.el6_1 | Fixed | RHSA-2011:1441 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.22% (0.02217) | 82.02th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.22% (0.02217) | 80.28th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.97% (0.00971) | 74.61th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.94% (0.02935) | 77.36th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.05% (0.01050) | 76.01th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.41% (0.00409) | 74.69th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.34% (0.00340) | 70.62th | v3 (v2023.03.01) |
| Sep 18, 2023 | 0.34% (0.00340) | 67.96th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.35% (0.00347) | 67.14th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.41% (0.01408) | 72.89th | v2 (v2022.01.01) |
| Mar 2, 2023 | 1.41% (0.01408) | 72.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.41% (0.01408) | 70.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.41% (0.01408) | 49.94th | v2 (v2022.01.01) |
References (11)
- http://dbhole.wordpress.com/2011/11/08/icedtea-web-1-0-6-and-1-1-4-security-releases-released/ x_refsource_CONFIRMPatchVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2012-03/msg00028.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2011-1441.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2012/dsa-2420 vendor-advisoryx_refsource_DEBIAN
- http://www.osvdb.org/76940 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/50610 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1263-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2011-3377 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=742515 x_refsource_MISCIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2011-3377
- https://www.cve.org/CVERecord?id=CVE-2011-3377
| Link | Providers | Tags |
|---|---|---|
| http://dbhole.wordpress.com/2011/11/08/icedtea-web-1-0-6-and-1-1-4-security-releases-released/ | x_refsource_CONFIRMPatchVendor Advisory | |
| http://lists.opensuse.org/opensuse-updates/2012-03/msg00028.html | vendor-advisoryx_refsource_SUSE | |
| http://rhn.redhat.com/errata/RHSA-2011-1441.html | vendor-advisoryx_refsource_REDHAT | |
| http://www.debian.org/security/2012/dsa-2420 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.osvdb.org/76940 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/50610 | vdb-entryx_refsource_BID | |
| http://www.ubuntu.com/usn/USN-1263-1 | vendor-advisoryx_refsource_UBUNTU | |
| https://access.redhat.com/security/cve/CVE-2011-3377 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=742515 | x_refsource_MISCIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2011-3377 | ||
| https://www.cve.org/CVERecord?id=CVE-2011-3377 |
Change history (0)
No recorded changes yet.