Show filters
45 Total Results
Displaying 1-10 of 45
Sort by:
Attacker Value
Unknown

CVE-2024-6473

Disclosure Date: September 03, 2024 (last updated September 06, 2024)
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
Attacker Value
Unknown

CVE-2023-34173

Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Semikashev Yandex Metrica Counter plugin <= 1.4.3 versions.
Attacker Value
Unknown

CVE-2023-29751

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.
Attacker Value
Unknown

CVE-2023-29749

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.
Attacker Value
Unknown

CVE-2023-22721

Disclosure Date: January 23, 2023 (last updated November 08, 2023)
Auth. Stored Cross-Site Scripting (XSS) in Oi Yandex.Maps for WordPress <= 3.2.7 versions.
Attacker Value
Unknown

CVE-2022-28226

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
Attacker Value
Unknown

CVE-2022-28225

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Attacker Value
Unknown

CVE-2021-25261

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Attacker Value
Unknown

CVE-2021-42391

Disclosure Date: March 14, 2022 (last updated October 07, 2023)
Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.
Attacker Value
Unknown

CVE-2021-42390

Disclosure Date: March 14, 2022 (last updated October 07, 2023)
Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.