VYPR

Avant Browser

Sign in to watch

by Avantbrowser

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2008-41660.030.06Sep 22, 2008Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a denial of service (application crash) by attempting to URL encode a string containing many instances of an invalid character.
CVE-2006-20580.000.01Apr 26, 2006Argument injection vulnerability in Avant Browser 10.1 Build 17 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.