Netsurf Browser
Products
3- 4 CVEs
- 2 CVEs
- 2 CVEs
Recent CVEs
8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-7505 | Hig | 0.57 | 8.8 | 0.03 | Feb 18, 2020 | Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file. | ||
| CVE-2015-7508 | Hig | 0.57 | 8.8 | 0.03 | Feb 12, 2020 | Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file. | ||
| CVE-2015-7507 | Hig | 0.49 | 7.5 | 0.02 | Feb 18, 2020 | libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function. | ||
| CVE-2025-45663 | Med | 0.42 | 6.5 | 0.00 | Nov 3, 2025 | An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure. | ||
| CVE-2025-29699 | Med | 0.42 | 6.5 | 0.00 | Nov 3, 2025 | NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. | ||
| CVE-2024-51317 | Med | 0.42 | 6.5 | 0.00 | Nov 3, 2025 | An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function | ||
| CVE-2015-7506 | Med | 0.42 | 6.5 | 0.01 | Feb 18, 2020 | The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file. | ||
| CVE-2012-0844 | Med | 0.36 | 5.5 | 0.00 | Feb 21, 2020 | Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar. |
- risk 0.57cvss 8.8epss 0.03
Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.
- risk 0.57cvss 8.8epss 0.03
Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.
- risk 0.49cvss 7.5epss 0.02
libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.
- risk 0.42cvss 6.5epss 0.00
An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
- risk 0.42cvss 6.5epss 0.00
NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.
- risk 0.42cvss 6.5epss 0.00
An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function
- risk 0.42cvss 6.5epss 0.01
The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.
- risk 0.36cvss 5.5epss 0.00
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.