4.3
CVSSv2

CVE-2017-18256

Published: 04/04/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Brave Browser prior to 0.13.0 allows remote malicious users to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code, because window dialogs are mishandled.

Vulnerable Product Search on Vulmon Subscribe to Product

brave brave browser

Exploits

# Exploit Title:Brave Browser < 0130 Denial of Service (resource consumption) via a long alert() argument # Date: 2017-10-16 # Exploit Author: Sahil Tikoo # Vendor Homepage: bravecom # Software Link: githubcom/brave/browser-laptop # Version: 0125 # Tested on: Kali Linux,Ubuntu ,Windows OS # CVE : CVE-2017-18256 #PoC < ...
Brave Browser versions prior to 0130 suffer from a long alert() argument denial of service vulnerability ...