Show filters
557 Total Results
Displaying 151-160 of 557
Sort by:
Attacker Value
Unknown

CVE-2016-4075

Disclosure Date: April 21, 2017 (last updated November 26, 2024)
Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.
Attacker Value
Unknown

CVE-2016-9473

Disclosure Date: March 28, 2017 (last updated November 26, 2024)
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.
Attacker Value
Unknown

CVE-2016-8508

Disclosure Date: March 01, 2017 (last updated November 26, 2024)
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
Attacker Value
Unknown

CVE-2016-8507

Disclosure Date: March 01, 2017 (last updated November 26, 2024)
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.
Attacker Value
Unknown

CVE-2016-3180

Disclosure Date: February 07, 2017 (last updated November 26, 2024)
Tor Browser Launcher (aka torbrowser-launcher) before 0.2.4, during the initial run, allows man-in-the-middle attackers to bypass the PGP signature verification and execute arbitrary code via a Trojan horse tar file and a signature file with the valid tarball and signature.
0
Attacker Value
Unknown

CVE-2016-6908

Disclosure Date: January 26, 2017 (last updated November 25, 2024)
Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are rendered combined with (first strong character) such as an IP address or alphabet could lead to a spoofed URL. It was noticed that by placing neutral characters such as "/", "?" in filepath causes the URL to be flipped and displayed from Right To Left. However, in order for the URL to be spoofed the URL must begin with an IP address followed by neutral characters as omnibox considers IP address to be combination of punctuation and numbers and since LTR (Left To Right) direction is not properly enforced, this causes the entire URL to be treated and rendered from RTL (Right To Left). However, it doesn't have be an IP address, what matters is that first strong character (generally, alphabetic character) in the URL must be an RTL character.
0
Attacker Value
Unknown

CVE-2016-8506

Disclosure Date: October 26, 2016 (last updated November 25, 2024)
XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.
0
Attacker Value
Unknown

CVE-2016-8501

Disclosure Date: October 26, 2016 (last updated November 25, 2024)
Security WiFi bypass in Yandex Browser from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected wi-fi networks despite of special security mechanism is enabled.
0
Attacker Value
Unknown

CVE-2016-8505

Disclosure Date: October 26, 2016 (last updated November 25, 2024)
XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary javascript code.
0
Attacker Value
Unknown

CVE-2016-8504

Disclosure Date: October 26, 2016 (last updated November 25, 2024)
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.
0