İçeriğe atla
Noroxi

Brave kayıtları

brave üreticisine ait 24 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%16,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

24 kayıt
  • CVE-2016-10718
    34İzleyin

    Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.

    YüksekCVSS 7,5Kavram kanıtıEPSS %12

    brave · brave browser3 Nis 2018

  • CVE-2021-45884
    31İzleyin

    In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled,

    YüksekCVSS 7,5İstismar yokEPSS %3

    brave · brave27 Ara 2021

  • CVE-2024-37406
    30İzleyin

    In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to dom

    YüksekCVSS 7,5İstismar yokEPSS %0

    brave · android browser18 Eyl 2024

  • CVE-2017-18256
    27İzleyin

    Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaS

    OrtaCVSS 6,5Kavram kanıtıEPSS %5

    brave · brave browser3 Nis 2018

  • CVE-2021-22917
    26İzleyin

    Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowi

    OrtaCVSS 6,5İstismar yokEPSS %1

    brave · browser12 Tem 2021

  • CVE-2017-8458
    26İzleyin

    Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://safe.example.com@unsafe.example.com/ is displayed without a clear

    OrtaCVSS 6,5İstismar yokEPSS %1

    brave · brave3 May 2017

  • CVE-2022-47932
    26İzleyin

    Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns

    OrtaCVSS 6,5İstismar yokEPSS %1

    brave · brave24 Ara 2022

  • CVE-2022-47934
    26İzleyin

    Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file tha

    OrtaCVSS 6,5İstismar yokEPSS %1

    brave · brave24 Ara 2022

  • CVE-2022-47933
    26İzleyin

    Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme.

    OrtaCVSS 6,5İstismar yokEPSS %1

    brave · brave24 Ara 2022

  • CVE-2018-10798
    26İzleyin

    A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux).

    OrtaCVSS 6,5İstismar yokEPSS %1

    brave · brave8 May 2018

  • CVE-2018-10799
    26İzleyin

    A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux).

    OrtaCVSS 6,5İstismar yokEPSS %1

    brave · brave8 May 2018

  • CVE-2021-22916
    24İzleyin

    In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblock

    OrtaCVSS 5,9İstismar yokEPSS %3

    brave · brave12 Tem 2021

  • CVE-2021-22929
    24İzleyin

    An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps o

    OrtaCVSS 6,1İstismar yokEPSS %1

    brave · brave31 Ağu 2021

  • CVE-2023-22798
    24İzleyin

    Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websi

    OrtaCVSS 6,1İstismar yokEPSS %0

    brave · adblock-lists9 Şub 2023

  • CVE-2023-52263
    24İzleyin

    Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect.

    OrtaCVSS 6,1İstismar yokEPSS %0

    brave · browser30 Ara 2023

  • CVE-2023-28364
    24İzleyin

    An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned

    OrtaCVSS 6,1İstismar yokEPSS %0

    brave · browser30 Haz 2023

  • CVE-2022-30334
    22İzleyin

    Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers.

    OrtaCVSS 5,3İstismar yokEPSS %3

    brave · brave7 May 2022

  • CVE-2021-21323
    22İzleyin

    Regression in DNS leakage from Tor windows

    OrtaCVSS 5,3İstismar yokEPSS %2

    brave · brave23 Şub 2021

  • CVE-2020-8276
    22İzleyin

    The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the use

    OrtaCVSS 5,5İstismar yokEPSS %0

    brave · brave9 Kas 2020

  • CVE-2017-8459
    21İzleyin

    Brave 0.12.4 has a Status Bar Obfuscation issue in which a redirection target is shown in a possibly unexpected way.

    OrtaCVSS 5,3İstismar yokEPSS %1

    brave · brave3 May 2017

  • CVE-2016-9473
    19İzleyin

    Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to tr

    OrtaCVSS 4,7İstismar yokEPSS %2

    brave · browser27 Mar 2017

  • Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting b

    OrtaCVSS 4,7İstismar yokEPSS %1

    brave · browser3 Oca 2018

  • Brave Software Inc.

    OrtaCVSS 4,3İstismar yokEPSS %1

    brave · brave20 Ara 2018

  • CVE-2023-28360
    17İzleyin

    An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file t

    OrtaCVSS 4,3İstismar yokEPSS %1

    brave · brave11 May 2023