maxthon records
10 published records for vendor maxthon.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-284 Improper Access Control1
- CWE-428 Unquoted Search Path or Element1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2005-1091No exploit | Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes tmaxthon · maxthon | High7.5 | — | 1.7% | May 2, 2005 |
29Monitor | CVE-2008-3667Proof of concept | Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTmaxthon · maxthon browser · CWE-119 | Medium6.8 | — | 6.9% | Aug 13, 2008 |
29Monitor | CVE-2019-16647No exploit | Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.maxthon · maxthon browser · CWE-428 | High7.2 | — | 2.0% | Oct 29, 2019 |
27Monitor | CVE-2010-5246No exploit | Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan horsmaxthon · maxthon browser | Medium6.9 | — | 0.4% | Sep 7, 2012 |
26Monitor | CVE-2005-1090No exploit | Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbmaxthon · maxthon | Medium6.4 | — | 1.9% | May 2, 2005 |
21Monitor | CVE-2014-1449No exploit | The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript maxthon · maxthon cloud browser · CWE-284 | Medium5.0 | — | 1.9% | Dec 25, 2014 |
20Monitor | CVE-2006-6985No exploit | Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an objemaxthon · maxthon | Medium5.0 | — | 1.1% | Feb 8, 2007 |
17Monitor | CVE-2009-3018No exploit | Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, whicmaxthon · maxthon browser · CWE-79 | Medium4.3 | — | 1.1% | Aug 31, 2009 |
17Monitor | CVE-2009-3006No exploit | Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrarymaxthon · maxthon browser | Medium4.3 | — | 1.0% | Aug 28, 2009 |
11Monitor | CVE-2005-0905Proof of concept | Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.maxthon · maxthon | Low2.6 | — | 2.3% | May 2, 2005 |
- CVE-2005-109131Monitor
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes t
HighCVSS 7.5No exploitEPSS 2%maxthon · maxthonMay 2, 2005
- CVE-2008-366729Monitor
Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTT
MediumCVSS 6.8Proof of conceptEPSS 7%maxthon · maxthon browserAug 13, 2008
- CVE-2019-1664729Monitor
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
HighCVSS 7.2No exploitEPSS 2%maxthon · maxthon browserOct 29, 2019
- CVE-2010-524627Monitor
Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan hors
MediumCVSS 6.9No exploitEPSS 0%maxthon · maxthon browserSep 7, 2012
- CVE-2005-109026Monitor
Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arb
MediumCVSS 6.4No exploitEPSS 2%maxthon · maxthonMay 2, 2005
- CVE-2014-144921Monitor
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript
MediumCVSS 5.0No exploitEPSS 2%maxthon · maxthon cloud browserDec 25, 2014
- CVE-2006-698520Monitor
Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an obje
MediumCVSS 5.0No exploitEPSS 1%maxthon · maxthonFeb 8, 2007
- CVE-2009-301817Monitor
Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, whic
MediumCVSS 4.3No exploitEPSS 1%maxthon · maxthon browserAug 31, 2009
- CVE-2009-300617Monitor
Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary
MediumCVSS 4.3No exploitEPSS 1%maxthon · maxthon browserAug 28, 2009
- CVE-2005-090511Monitor
Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.
LowCVSS 2.6Proof of conceptEPSS 2%maxthon · maxthonMay 2, 2005