Show filters
557 Total Results
Displaying 81-90 of 557
Sort by:
Attacker Value
Unknown

CVE-2021-23364

Disclosure Date: April 28, 2021 (last updated February 22, 2025)
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
Attacker Value
Unknown

CVE-2021-29370

Disclosure Date: April 13, 2021 (last updated February 22, 2025)
A UXSS was discovered in the Thanos-Soft Cheetah Browser in Android 1.2.0 due to the inadequate filter of the intent scheme. This resulted in Cross-site scripting on the cheetah browser in any website.
Attacker Value
Unknown

CVE-2020-26282

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it is especially useful when embedded in Selenium tests. A Server-Side Template Injection was identified in BrowserUp Proxy enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. This has been patched in version 2.1.2.
Attacker Value
Unknown

CVE-2020-7790

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
0
Attacker Value
Unknown

CVE-2020-27146

Disclosure Date: November 10, 2020 (last updated February 22, 2025)
The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human interaction from an authenticated user other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser): versions 11.6.0 and below.
Attacker Value
Unknown

CVE-2020-7370

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Bolt Browser version 1.4 and prior versions.
Attacker Value
Unknown

CVE-2020-7371

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions.
Attacker Value
Unknown

CVE-2020-7364

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 and prior versions.
Attacker Value
Unknown

CVE-2020-7363

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 and prior versions.
Attacker Value
Unknown

CVE-2020-7369

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 and prior versions, and was fixed in version 20.8.4 released October 1, 2020.