Show filters
557 Total Results
Displaying 161-170 of 557
Sort by:
Attacker Value
Unknown
CVE-2016-8502
Disclosure Date: October 26, 2016 (last updated November 25, 2024)
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
0
Attacker Value
Unknown
CVE-2016-8503
Disclosure Date: October 26, 2016 (last updated November 25, 2024)
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
0
Attacker Value
Unknown
CVE-2016-7153
Disclosure Date: September 06, 2016 (last updated November 25, 2024)
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
0
Attacker Value
Unknown
CVE-2016-6231
Disclosure Date: August 25, 2016 (last updated November 25, 2024)
Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2015-6862
Disclosure Date: January 08, 2016 (last updated November 25, 2024)
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-4000
Disclosure Date: May 21, 2015 (last updated October 23, 2024)
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
0
Attacker Value
Unknown
CVE-2014-9392
Disclosure Date: December 31, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the PictoBrowser (pictobrowser-gallery) plugin 0.3.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the pictoBrowserFlickrUser parameter in the options-page.php page to wp-admin/options-general.php.
0
Attacker Value
Unknown
CVE-2014-1449
Disclosure Date: December 25, 2014 (last updated October 05, 2023)
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.
0
Attacker Value
Unknown
CVE-2014-4905
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Clean Internet Browser (aka com.cleantab.browsesecure) application 1.36 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7466
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Live TV Browser (aka com.wHDSmartBrowser) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0