Skip to content
Noroxi

maxthon records

10 published records for vendor maxthon.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

10 records
  • CVE-2005-1091
    31Monitor

    Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes t

    HighCVSS 7.5No exploitEPSS 2%

    maxthon · maxthonMay 2, 2005

  • CVE-2008-3667
    29Monitor

    Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTT

    MediumCVSS 6.8Proof of conceptEPSS 7%

    maxthon · maxthon browserAug 13, 2008

  • Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.

    HighCVSS 7.2No exploitEPSS 2%

    maxthon · maxthon browserOct 29, 2019

  • CVE-2010-5246
    27Monitor

    Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan hors

    MediumCVSS 6.9No exploitEPSS 0%

    maxthon · maxthon browserSep 7, 2012

  • CVE-2005-1090
    26Monitor

    Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arb

    MediumCVSS 6.4No exploitEPSS 2%

    maxthon · maxthonMay 2, 2005

  • CVE-2014-1449
    21Monitor

    The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript

    MediumCVSS 5.0No exploitEPSS 2%

    maxthon · maxthon cloud browserDec 25, 2014

  • CVE-2006-6985
    20Monitor

    Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an obje

    MediumCVSS 5.0No exploitEPSS 1%

    maxthon · maxthonFeb 8, 2007

  • CVE-2009-3018
    17Monitor

    Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, whic

    MediumCVSS 4.3No exploitEPSS 1%

    maxthon · maxthon browserAug 31, 2009

  • CVE-2009-3006
    17Monitor

    Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary

    MediumCVSS 4.3No exploitEPSS 1%

    maxthon · maxthon browserAug 28, 2009

  • CVE-2005-0905
    11Monitor

    Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.

    LowCVSS 2.6Proof of conceptEPSS 2%

    maxthon · maxthonMay 2, 2005