Записи maxthon
10 опубликованных записей вендора maxthon.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-284 Improper Access Control1
- CWE-428 Unquoted Search Path or Element1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2005-1091Эксплойта нет | Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes tmaxthon · maxthon | Высокая7,5 | — | 1,7 % | 2 мая 2005 г. |
29Наблюдать | CVE-2008-3667Proof of concept | Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTmaxthon · maxthon browser · CWE-119 | Средняя6,8 | — | 6,9 % | 13 авг. 2008 г. |
29Наблюдать | CVE-2019-16647Эксплойта нет | Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.maxthon · maxthon browser · CWE-428 | Высокая7,2 | — | 2,0 % | 29 окт. 2019 г. |
27Наблюдать | CVE-2010-5246Эксплойта нет | Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan horsmaxthon · maxthon browser | Средняя6,9 | — | 0,4 % | 7 сент. 2012 г. |
26Наблюдать | CVE-2005-1090Эксплойта нет | Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbmaxthon · maxthon | Средняя6,4 | — | 1,9 % | 2 мая 2005 г. |
21Наблюдать | CVE-2014-1449Эксплойта нет | The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript maxthon · maxthon cloud browser · CWE-284 | Средняя5,0 | — | 1,9 % | 25 дек. 2014 г. |
20Наблюдать | CVE-2006-6985Эксплойта нет | Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an objemaxthon · maxthon | Средняя5,0 | — | 1,1 % | 8 февр. 2007 г. |
17Наблюдать | CVE-2009-3018Эксплойта нет | Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, whicmaxthon · maxthon browser · CWE-79 | Средняя4,3 | — | 1,1 % | 31 авг. 2009 г. |
17Наблюдать | CVE-2009-3006Эксплойта нет | Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrarymaxthon · maxthon browser | Средняя4,3 | — | 1,0 % | 28 авг. 2009 г. |
11Наблюдать | CVE-2005-0905Proof of concept | Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.maxthon · maxthon | Низкая2,6 | — | 2,3 % | 2 мая 2005 г. |
- CVE-2005-109131Наблюдать
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %maxthon · maxthon2 мая 2005 г.
- CVE-2008-366729Наблюдать
Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTT
СредняяCVSS 6,8Proof of conceptEPSS 7 %maxthon · maxthon browser13 авг. 2008 г.
- CVE-2019-1664729Наблюдать
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %maxthon · maxthon browser29 окт. 2019 г.
- CVE-2010-524627Наблюдать
Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan hors
СредняяCVSS 6,9Эксплойта нетEPSS 0 %maxthon · maxthon browser7 сент. 2012 г.
- CVE-2005-109026Наблюдать
Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arb
СредняяCVSS 6,4Эксплойта нетEPSS 2 %maxthon · maxthon2 мая 2005 г.
- CVE-2014-144921Наблюдать
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript
СредняяCVSS 5,0Эксплойта нетEPSS 2 %maxthon · maxthon cloud browser25 дек. 2014 г.
- CVE-2006-698520Наблюдать
Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an obje
СредняяCVSS 5,0Эксплойта нетEPSS 1 %maxthon · maxthon8 февр. 2007 г.
- CVE-2009-301817Наблюдать
Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, whic
СредняяCVSS 4,3Эксплойта нетEPSS 1 %maxthon · maxthon browser31 авг. 2009 г.
- CVE-2009-300617Наблюдать
Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary
СредняяCVSS 4,3Эксплойта нетEPSS 1 %maxthon · maxthon browser28 авг. 2009 г.
- CVE-2005-090511Наблюдать
Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.
НизкаяCVSS 2,6Proof of conceptEPSS 2 %maxthon · maxthon2 мая 2005 г.