← Vulnerability feed

Vulnerability record · CVE-2012-3422 · published 7 August 2012

CVE-2012-3422: Redhat icedtea-web memory buffer overflow vulnerability

Redhat · Icedtea Web

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

6.8 CVSS 2.0 Medium EPSS 3.1% · top 12.7% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00030.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00101.html
http://rhn.redhat.com/errata/RHSA-2012-1132.html
http://secunia.com/advisories/50089 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.ubuntu.com/usn/USN-1521-1
https://bugzilla.redhat.com/show_bug.cgi?id=840592
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00030.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00101.html
http://rhn.redhat.com/errata/RHSA-2012-1132.html
http://secunia.com/advisories/50089 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.ubuntu.com/usn/USN-1521-1
https://bugzilla.redhat.com/show_bug.cgi?id=840592

Track CVE-2012-3422 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2012-3423Redhat icedtea-web memory buffer overflow vulnerabilityThe IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a de…EPSS 6.2%7.5CVE-2011-0706Redhat icedtea-web permissions and access controls vulnerabilityThe JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via u…EPSS 3.1%6.8CVE-2011-2514Redhat icedtea-web permissions and access controls vulnerabilityThe Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…EPSS 2.4%6.8CVE-2013-1927Redhat icedtea-web vulnerabilityThe IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as bot…EPSS 4.3%6.8CVE-2012-4540Opensuse vulnerabilityOff-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1…EPSS 3.4%5.8CVE-2013-1926Redhat icedtea-web vulnerabilityThe IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different doma…EPSS 1.9%5.0CVE-2011-2513Redhat icedtea-web information exposure vulnerabilityThe Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…EPSS 2.5%4.3CVE-2011-3377Redhat icedtea-web permissions and access controls vulnerabilityThe web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and e…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2012-3422), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.