Show filters
557 Total Results
Displaying 141-150 of 557
Sort by:
Attacker Value
Unknown
CVE-2017-7327
Disclosure Date: January 19, 2018 (last updated November 26, 2024)
Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll or profapi.dll.
0
Attacker Value
Unknown
CVE-2018-5326
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Cheetah Mobile CM Browser 5.22.06.0012, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.
0
Attacker Value
Unknown
CVE-2018-5327
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.
0
Attacker Value
Unknown
CVE-2017-18016
Disclosure Date: January 11, 2018 (last updated November 26, 2024)
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an origin).
0
Attacker Value
Unknown
CVE-2017-1000461
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block).
0
Attacker Value
Unknown
CVE-2017-17859
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another part of this MHTML file does not have a document.domain value corresponding to the domain that is hosting the MHTML file, but instead has a document.domain value corresponding to an arbitrary URL within the content of the MHTML file.
0
Attacker Value
Unknown
CVE-2017-17692
Disclosure Date: December 21, 2017 (last updated November 26, 2024)
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
0
Attacker Value
Unknown
CVE-2014-0073
Disclosure Date: October 30, 2017 (last updated November 08, 2023)
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript in the host page and consequently gain privileges via a crafted gap-iab: URI.
0
Attacker Value
Unknown
CVE-2017-12707
Disclosure Date: August 25, 2017 (last updated November 26, 2024)
A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow.
0
Attacker Value
Unknown
CVE-2017-8936
Disclosure Date: May 15, 2017 (last updated November 08, 2023)
The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0