← Vulnerability feed

Vulnerability record · CVE-2012-3423 · published 7 August 2012

CVE-2012-3423: Redhat icedtea-web memory buffer overflow vulnerability

Redhat · Icedtea Web

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

7.5 CVSS 2.0 High EPSS 6.2% · top 6.8% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
6.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=518
http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=863 Vendor Advisory
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d65bd94e0ba9 ExploitPatch
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d7375e2a9076 ExploitPatch
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00030.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00101.html
http://rhn.redhat.com/errata/RHSA-2012-1132.html
http://secunia.com/advisories/50089 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.ubuntu.com/usn/USN-1521-1
https://bugzilla.redhat.com/show_bug.cgi?id=841345
http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=518
http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=863 Vendor Advisory
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d65bd94e0ba9 ExploitPatch
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d7375e2a9076 ExploitPatch
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00030.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00101.html
http://rhn.redhat.com/errata/RHSA-2012-1132.html
http://secunia.com/advisories/50089 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.ubuntu.com/usn/USN-1521-1
https://bugzilla.redhat.com/show_bug.cgi?id=841345

Track CVE-2012-3423 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2011-0706Redhat icedtea-web permissions and access controls vulnerabilityThe JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via u…EPSS 3.1%6.8CVE-2011-2514Redhat icedtea-web permissions and access controls vulnerabilityThe Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…EPSS 2.4%6.8CVE-2013-1927Redhat icedtea-web vulnerabilityThe IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as bot…EPSS 4.3%6.8CVE-2012-4540Opensuse vulnerabilityOff-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1…EPSS 3.4%6.8CVE-2012-3422Redhat icedtea-web memory buffer overflow vulnerabilityThe getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empt…EPSS 3.1%5.8CVE-2013-1926Redhat icedtea-web vulnerabilityThe IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different doma…EPSS 1.9%5.0CVE-2011-2513Redhat icedtea-web information exposure vulnerabilityThe Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…EPSS 2.5%4.3CVE-2011-3377Redhat icedtea-web permissions and access controls vulnerabilityThe web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and e…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2012-3423), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.