Filtered by vendor Yandex
Subscribe
Total
43 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-7325 | 1 Yandex | 1 Yandex Browser | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open. | |||||
CVE-2016-10666 | 1 Yandex | 1 Tomita-parser | 2024-11-21 | 9.3 HIGH | 8.1 HIGH |
tomita-parser is a Node wrapper for Yandex Tomita Parser tomita-parser downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server. | |||||
CVE-2024-6473 | 1 Yandex | 1 Yandex Browser | 2024-09-05 | N/A | 7.8 HIGH |
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used. |