Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2023-26081
Disclosure Date: February 20, 2023 (last updated October 08, 2023)
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
0
Attacker Value
Unknown
CVE-2022-29536
Disclosure Date: April 20, 2022 (last updated October 07, 2023)
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
0
Attacker Value
Unknown
CVE-2021-45088
Disclosure Date: December 16, 2021 (last updated October 07, 2023)
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
0
Attacker Value
Unknown
CVE-2021-45087
Disclosure Date: December 16, 2021 (last updated October 07, 2023)
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
0
Attacker Value
Unknown
CVE-2021-45086
Disclosure Date: December 16, 2021 (last updated October 07, 2023)
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
0
Attacker Value
Unknown
CVE-2021-45085
Disclosure Date: December 16, 2021 (last updated October 07, 2023)
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
0
Attacker Value
Unknown
CVE-2019-6251
Disclosure Date: January 14, 2019 (last updated November 08, 2023)
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
0
Attacker Value
Unknown
CVE-2018-13467
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for EpiphanyCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2018-12016
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls.
0
Attacker Value
Unknown
CVE-2018-11396
Disclosure Date: May 23, 2018 (last updated November 26, 2024)
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.
0