It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.
Сообщаем режим работы подразделений ПАО КБ «Восточный»: Обслуживание физических лиц: Работа отделений и точек выдачи кредитов в магазинах и торговых центров вашего города осуществляется по следующему режиму: 31.12.2014 — до 16 часов местного времени; с 01.01.2015 по 07.01.2015 – выходные дни; с 08.01.2015 по 11.01.2015 – с 10.00 до 16.00 местного времени; с 12.01.2015 – [...]
Защита Renault Duster 4WD 1,6; 2,0; 1,5dC 2011-2015, 2015-/Nissan Terranо 4WD 1,6; 2,0 2014- редуктора + комплект крепежа Защита Renault Duster 4WD 1,6; 2,0; 1,5dC 2011-2015, 2015-/Nissan Terranо 4WD 1,6; 2,0 2014- редукто в наличии Цена: 900.00 ₽ КУПИТЬ
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.