VYPR
Vendor

Netsurf Browser

Products
3
CVEs
8
Across products
8
Status
Private

Products

3

Recent CVEs

8
  • CVE-2015-7505HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.03

    Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.

  • CVE-2015-7508HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.03

    Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.

  • CVE-2015-7507HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.02

    libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.

  • CVE-2025-45663MedNov 3, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

  • CVE-2025-29699MedNov 3, 2025
    risk 0.42cvss 6.5epss 0.00

    NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

  • CVE-2024-51317MedNov 3, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

  • CVE-2015-7506MedFeb 18, 2020
    risk 0.42cvss 6.5epss 0.01

    The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.

  • CVE-2012-0844MedFeb 21, 2020
    risk 0.36cvss 5.5epss 0.00

    Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.