Whale Browser Installer
by Naver
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-9753 | Cri | 0.59 | 9.1 | 0.01 | May 20, 2020 | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. | ||
| CVE-2020-9754 | Med | 0.35 | 5.3 | 0.01 | Jun 27, 2022 | NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode. | ||
| CVE-2018-12448 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2018 | Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allows an attacker to display a malicious web page with a fake domain name. | ||
| CVE-2018-7635 | Med | 0.35 | 5.3 | 0.01 | Jul 3, 2018 | Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domain name. |
- risk 0.59cvss 9.1epss 0.01
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
- risk 0.35cvss 5.3epss 0.01
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.
- risk 0.35cvss 5.3epss 0.01
Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allows an attacker to display a malicious web page with a fake domain name.
- risk 0.35cvss 5.3epss 0.01
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domain name.