Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
yandex vulnerabilities and exploits
(subscribe to this query)
5.1
CVSSv2
CVE-2017-7326
Race condition issue in Yandex Browser for Android prior to 17.4.0.16 allowed a remote malicious user to potentially exploit memory corruption via a crafted HTML page
Yandex Yandex Browser
4.3
CVSSv2
CVE-2016-8508
Yandex Browser for desktop prior to 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
Yandex Yandex Browser
5
CVSSv2
CVE-2017-7325
Yandex Browser prior to 16.9.0 allows remote malicious users to spoof the address bar via window.open.
Yandex Yandex Browser
6.8
CVSSv2
CVE-2017-7327
Yandex Browser installer for Desktop prior to 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll or profapi.dll.
Yandex Yandex Browser
4.6
CVSSv2
CVE-2021-25263
Local privilege vulnerability in Yandex Browser for Windows before 21.9.0.390 allows a local, low privileged, malicious user to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
Yandex Yandex Browser
NA
CVE-2023-34173
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Semikashev Yandex Metrica Counter plugin <= 1.4.3 versions.
Yandex Metrica Counter Project Yandex Metric Counter
7.2
CVSSv2
CVE-2022-28225
Local privilege vulnerability in Yandex Browser for Windows before 22.3.3.684 allows a local, low privileged, malicious user to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Yandex Yandex Browser
7.2
CVSSv2
CVE-2022-28226
Local privilege vulnerability in Yandex Browser for Windows before 22.3.3.801 allows a local, low privileged, malicious user to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser updat...
Yandex Yandex Browser
7.5
CVSSv2
CVE-2019-16535
In all versions of ClickHouse prior to 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
Yandex Clickhouse
5
CVSSv2
CVE-2019-18657
ClickHouse prior to 19.13.5.44 allows HTTP header injection via the url table function.
Yandex Clickhouse
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »