maxthon kayıtları
maxthon üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-284 Improper Access Control1
- CWE-428 Unquoted Search Path or Element1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2005-1091İstismar yok | Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes tmaxthon · maxthon | Yüksek7,5 | — | %1,7 | 2 May 2005 |
29İzleyin | CVE-2008-3667Kavram kanıtı | Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTmaxthon · maxthon browser · CWE-119 | Orta6,8 | — | %6,9 | 13 Ağu 2008 |
29İzleyin | CVE-2019-16647İstismar yok | Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.maxthon · maxthon browser · CWE-428 | Yüksek7,2 | — | %2,0 | 29 Eki 2019 |
27İzleyin | CVE-2010-5246İstismar yok | Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan horsmaxthon · maxthon browser | Orta6,9 | — | %0,4 | 7 Eyl 2012 |
26İzleyin | CVE-2005-1090İstismar yok | Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbmaxthon · maxthon | Orta6,4 | — | %1,9 | 2 May 2005 |
21İzleyin | CVE-2014-1449İstismar yok | The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript maxthon · maxthon cloud browser · CWE-284 | Orta5,0 | — | %1,9 | 25 Ara 2014 |
20İzleyin | CVE-2006-6985İstismar yok | Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an objemaxthon · maxthon | Orta5,0 | — | %1,1 | 8 Şub 2007 |
17İzleyin | CVE-2009-3018İstismar yok | Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, whicmaxthon · maxthon browser · CWE-79 | Orta4,3 | — | %1,1 | 31 Ağu 2009 |
17İzleyin | CVE-2009-3006İstismar yok | Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrarymaxthon · maxthon browser | Orta4,3 | — | %1,0 | 28 Ağu 2009 |
11İzleyin | CVE-2005-0905Kavram kanıtı | Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.maxthon · maxthon | Düşük2,6 | — | %2,3 | 2 May 2005 |
- CVE-2005-109131İzleyin
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes t
YüksekCVSS 7,5İstismar yokEPSS %2maxthon · maxthon2 May 2005
- CVE-2008-366729İzleyin
Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTT
OrtaCVSS 6,8Kavram kanıtıEPSS %7maxthon · maxthon browser13 Ağu 2008
- CVE-2019-1664729İzleyin
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
YüksekCVSS 7,2İstismar yokEPSS %2maxthon · maxthon browser29 Eki 2019
- CVE-2010-524627İzleyin
Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan hors
OrtaCVSS 6,9İstismar yokEPSS %0maxthon · maxthon browser7 Eyl 2012
- CVE-2005-109026İzleyin
Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arb
OrtaCVSS 6,4İstismar yokEPSS %2maxthon · maxthon2 May 2005
- CVE-2014-144921İzleyin
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript
OrtaCVSS 5,0İstismar yokEPSS %2maxthon · maxthon cloud browser25 Ara 2014
- CVE-2006-698520İzleyin
Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an obje
OrtaCVSS 5,0İstismar yokEPSS %1maxthon · maxthon8 Şub 2007
- CVE-2009-301817İzleyin
Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, whic
OrtaCVSS 4,3İstismar yokEPSS %1maxthon · maxthon browser31 Ağu 2009
- CVE-2009-300617İzleyin
Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary
OrtaCVSS 4,3İstismar yokEPSS %1maxthon · maxthon browser28 Ağu 2009
- CVE-2005-090511İzleyin
Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.
DüşükCVSS 2,6Kavram kanıtıEPSS %2maxthon · maxthon2 May 2005