UCWeb records
8 published records for vendor ucweb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-451 User Interface (UI) Misrepresentation of Critical Information2
- CWE-1021 Improper Restriction of Rendered UI Layers or Frames1
- CWE-310 Cryptographic Issues1
- CWE-312 Cleartext Storage of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2012-1478No exploit | Unspecified vulnerability in the UCMobile BloveStorm (com.blovestorm) application 2.2.0 and 3.2.1 for Android has unknown impact and attack ucweb · ucmobile blovestorm | Critical10.0 | — | 1.7% | Mar 13, 2012 |
26Monitor | CVE-2017-20041No exploit | Ucweb UC Browser HTML URL improper restriction of rendered ui layersucweb · uc browser · CWE-1021 | Medium6.5 | — | 0.7% | Jun 13, 2022 |
23Monitor | CVE-2019-10251No exploit | The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Offiucweb · uc browser · CWE-319 | Medium5.9 | — | 0.8% | Mar 28, 2019 |
23Monitor | CVE-2019-10250No exploit | UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks.ucweb · uc browser · CWE-319 | Medium5.9 | — | 0.7% | Mar 28, 2019 |
21Monitor | CVE-2014-6691No exploit | The UC Browser HD (aka com.uc.browser.hd) application 3.3.1.469 for Android does not verify X.509 certificates from SSL servers, which allowucweb · uc browser hd · CWE-310 | Medium5.4 | — | 0.3% | Sep 23, 2014 |
17Monitor | CVE-2020-7363No exploit | UCWeb UC Browser Address Bar Spooofingucweb · uc browser · CWE-451 | Medium4.3 | — | 0.7% | Oct 20, 2020 |
17Monitor | CVE-2020-7364No exploit | UCWeb UC Browser Address Bar Spooofingucweb · uc browser · CWE-451 | Medium4.3 | — | 0.7% | Oct 20, 2020 |
14Monitor | CVE-2020-36473No exploit | UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.ucweb · ucweb uc · CWE-312 | Low3.7 | — | 0.5% | Aug 14, 2021 |
- CVE-2012-147840Plan
Unspecified vulnerability in the UCMobile BloveStorm (com.blovestorm) application 2.2.0 and 3.2.1 for Android has unknown impact and attack
CriticalCVSS 10.0No exploitEPSS 2%ucweb · ucmobile blovestormMar 13, 2012
- CVE-2017-2004126Monitor
Ucweb UC Browser HTML URL improper restriction of rendered ui layers
MediumCVSS 6.5No exploitEPSS 1%ucweb · uc browserJun 13, 2022
- CVE-2019-1025123Monitor
The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Offi
MediumCVSS 5.9No exploitEPSS 1%ucweb · uc browserMar 28, 2019
- CVE-2019-1025023Monitor
UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks.
MediumCVSS 5.9No exploitEPSS 1%ucweb · uc browserMar 28, 2019
- CVE-2014-669121Monitor
The UC Browser HD (aka com.uc.browser.hd) application 3.3.1.469 for Android does not verify X.509 certificates from SSL servers, which allow
MediumCVSS 5.4No exploitEPSS 0%ucweb · uc browser hdSep 23, 2014
- CVE-2020-736317Monitor
UCWeb UC Browser Address Bar Spooofing
MediumCVSS 4.3No exploitEPSS 1%ucweb · uc browserOct 20, 2020
- CVE-2020-736417Monitor
UCWeb UC Browser Address Bar Spooofing
MediumCVSS 4.3No exploitEPSS 1%ucweb · uc browserOct 20, 2020
- CVE-2020-3647314Monitor
UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.
LowCVSS 3.7No exploitEPSS 1%ucweb · ucweb ucAug 14, 2021