Show filters
557 Total Results
Displaying 71-80 of 557
Sort by:
Attacker Value
Unknown
CVE-2021-39246
Disclosure Date: September 24, 2021 (last updated February 23, 2025)
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network).
0
Attacker Value
Unknown
CVE-2021-20791
Disclosure Date: September 17, 2021 (last updated February 23, 2025)
Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-20790
Disclosure Date: September 17, 2021 (last updated February 23, 2025)
Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execute an arbitrary command or code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2020-27969
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
0
Attacker Value
Unknown
CVE-2020-27970
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
0
Attacker Value
Unknown
CVE-2021-37794
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to upload a malicious .svg file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger malicious OS commands on the server running the FileBrowser instance.
0
Attacker Value
Unknown
CVE-2021-25263
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
0
Attacker Value
Unknown
CVE-2021-24439
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped.
0
Attacker Value
Unknown
CVE-2021-22917
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled.
0
Attacker Value
Unknown
CVE-2021-1575
Disclosure Date: July 07, 2021 (last updated February 23, 2025)
A vulnerability in the web-based management interface of Cisco Virtualized Voice Browser could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
0