Show filters
557 Total Results
Displaying 91-100 of 557
Sort by:
Attacker Value
Unknown

CVE-2020-24158

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology.
Attacker Value
Unknown

CVE-2020-8954

Disclosure Date: June 08, 2020 (last updated February 21, 2025)
OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]
Attacker Value
Unknown

CVE-2020-9753

Disclosure Date: May 20, 2020 (last updated February 21, 2025)
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
Attacker Value
Unknown

CVE-2020-11054

Disclosure Date: May 07, 2020 (last updated February 21, 2025)
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly displayed as green (colors.statusbar.url.success_https). While the user already has seen a certificate error prompt at this point (or set content.ssl_strict to false, which is not recommended), this could still provide a false sense of security. This has been fixed in 1.11.1 and 1.12.0. All versions of qutebrowser are believed to be affected, though versions before v0.11.x couldn't be tested. Backported patches for older versions (greater than or equal to 1.4.0 and less than or equal to 1.10.2) are available, but no further releases are planned.
Attacker Value
Unknown

CVE-2020-10551

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious executable to the location of TsService.
Attacker Value
Unknown

CVE-2020-11000

Disclosure Date: April 08, 2020 (last updated February 21, 2025)
GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verification wrong, which allows an attacker to circumvent the access control. This problem has been patched in version 1.2.
Attacker Value
Unknown

CVE-2020-7625

Disclosure Date: April 02, 2020 (last updated February 21, 2025)
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
Attacker Value
Unknown

CVE-2011-4908

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
Attacker Value
Unknown

CVE-2011-4906

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
Attacker Value
Unknown

CVE-2014-4968

Disclosure Date: February 12, 2020 (last updated November 28, 2024)
The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attackers to execute arbitrary code via a crafted web site, a related issue to CVE-2012-6636.