Yandex.browser
by Yandex
CVEs (24)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25254 | Med | 0.34 | 5.3 | 0.01 | May 21, 2025 | Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar. | ||
| CVE-2020-7371 | Med | 0.28 | 4.3 | 0.01 | Oct 20, 2020 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions. | ||
| CVE-2020-7369 | Med | 0.28 | 4.3 | 0.01 | Oct 20, 2020 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 and prior versions, and… | ||
| CVE-2016-8504 | Med | 0.28 | 4.3 | 0.01 | Oct 26, 2016 | CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile. |
- risk 0.34cvss 5.3epss 0.01
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
- risk 0.28cvss 4.3epss 0.01
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions.
- risk 0.28cvss 4.3epss 0.01
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 and prior versions, and…
- risk 0.28cvss 4.3epss 0.01
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.
Page 2 of 2