Show filters
557 Total Results
Displaying 161-170 of 557
Sort by:
Attacker Value
Unknown

CVE-2016-8502

Disclosure Date: October 26, 2016 (last updated November 25, 2024)
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
0
Attacker Value
Unknown

CVE-2016-8503

Disclosure Date: October 26, 2016 (last updated November 25, 2024)
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
0
Attacker Value
Unknown

CVE-2016-7153

Disclosure Date: September 06, 2016 (last updated November 25, 2024)
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
0
Attacker Value
Unknown

CVE-2016-6231

Disclosure Date: August 25, 2016 (last updated November 25, 2024)
Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2015-6862

Disclosure Date: January 08, 2016 (last updated November 25, 2024)
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-4000

Disclosure Date: May 21, 2015 (last updated October 23, 2024)
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
0
Attacker Value
Unknown

CVE-2014-9392

Disclosure Date: December 31, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the PictoBrowser (pictobrowser-gallery) plugin 0.3.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the pictoBrowserFlickrUser parameter in the options-page.php page to wp-admin/options-general.php.
0
Attacker Value
Unknown

CVE-2014-1449

Disclosure Date: December 25, 2014 (last updated October 05, 2023)
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.
0
Attacker Value
Unknown

CVE-2014-4905

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Clean Internet Browser (aka com.cleantab.browsesecure) application 1.36 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7466

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Live TV Browser (aka com.wHDSmartBrowser) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0