Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-6473

Disclosure Date: September 03, 2024 (last updated September 06, 2024)
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
Attacker Value
Unknown

CVE-2022-28226

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
Attacker Value
Unknown

CVE-2022-28225

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Attacker Value
Unknown

CVE-2021-25261

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Attacker Value
Unknown

CVE-2020-27969

Disclosure Date: September 13, 2021 (last updated November 29, 2024)
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
Attacker Value
Unknown

CVE-2020-27970

Disclosure Date: September 13, 2021 (last updated November 29, 2024)
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
Attacker Value
Unknown

CVE-2021-25263

Disclosure Date: August 17, 2021 (last updated November 28, 2024)
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
Attacker Value
Unknown

CVE-2020-7369

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 and prior versions, and was fixed in version 20.8.4 released October 1, 2020.
Attacker Value
Unknown

CVE-2017-7326

Disclosure Date: January 19, 2018 (last updated November 26, 2024)
Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page
0
Attacker Value
Unknown

CVE-2017-7325

Disclosure Date: January 19, 2018 (last updated November 26, 2024)
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
0