Brave kayıtları
brave üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %16,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-20 Improper Input Validation5
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-755 Improper Handling of Exceptional Conditions1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2016-10718Kavram kanıtı | Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.brave · brave browser · CWE-20 | Yüksek7,5 | — | %12,2 | 3 Nis 2018 |
31İzleyin | CVE-2021-45884İstismar yok | In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, brave · brave · CWE-200 | Yüksek7,5 | — | %3,1 | 27 Ara 2021 |
30İzleyin | CVE-2024-37406İstismar yok | In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to dombrave · android browser · CWE-20 | Yüksek7,5 | — | %0,4 | 18 Eyl 2024 |
27İzleyin | CVE-2017-18256Kavram kanıtı | Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaSbrave · brave browser | Orta6,5 | — | %4,8 | 3 Nis 2018 |
26İzleyin | CVE-2021-22917İstismar yok | Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowibrave · browser · CWE-200 | Orta6,5 | — | %1,2 | 12 Tem 2021 |
26İzleyin | CVE-2017-8458İstismar yok | Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://safe.example.com@unsafe.example.com/ is displayed without a clearbrave · brave · CWE-74 | Orta6,5 | — | %1,1 | 3 May 2017 |
26İzleyin | CVE-2022-47932İstismar yok | Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipnsbrave · brave · CWE-400 | Orta6,5 | — | %1,1 | 24 Ara 2022 |
26İzleyin | CVE-2022-47934İstismar yok | Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file thabrave · brave · CWE-400 | Orta6,5 | — | %1,1 | 24 Ara 2022 |
26İzleyin | CVE-2022-47933İstismar yok | Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme.brave · brave · CWE-755 | Orta6,5 | — | %0,8 | 24 Ara 2022 |
26İzleyin | CVE-2018-10798İstismar yok | A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux).brave · brave · CWE-20 | Orta6,5 | — | %0,8 | 8 May 2018 |
26İzleyin | CVE-2018-10799İstismar yok | A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux).brave · brave · CWE-20 | Orta6,5 | — | %0,8 | 8 May 2018 |
24İzleyin | CVE-2021-22916İstismar yok | In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblockbrave · brave · CWE-200 | Orta5,9 | — | %3,0 | 12 Tem 2021 |
24İzleyin | CVE-2021-22929İstismar yok | An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps obrave · brave · CWE-312 | Orta6,1 | — | %0,6 | 31 Ağu 2021 |
24İzleyin | CVE-2023-22798İstismar yok | Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websibrave · adblock-lists · CWE-601 | Orta6,1 | — | %0,5 | 9 Şub 2023 |
24İzleyin | CVE-2023-52263İstismar yok | Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect.brave · browser · CWE-601 | Orta6,1 | — | %0,5 | 30 Ara 2023 |
24İzleyin | CVE-2023-28364İstismar yok | An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scannedbrave · browser · CWE-601 | Orta6,1 | — | %0,5 | 30 Haz 2023 |
22İzleyin | CVE-2022-30334İstismar yok | Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers.brave · brave · CWE-200 | Orta5,3 | — | %2,7 | 7 May 2022 |
22İzleyin | CVE-2021-21323İstismar yok | Regression in DNS leakage from Tor windowsbrave · brave · CWE-200 | Orta5,3 | — | %2,3 | 23 Şub 2021 |
22İzleyin | CVE-2020-8276İstismar yok | The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the usebrave · brave · CWE-312 | Orta5,5 | — | %0,4 | 9 Kas 2020 |
21İzleyin | CVE-2017-8459İstismar yok | Brave 0.12.4 has a Status Bar Obfuscation issue in which a redirection target is shown in a possibly unexpected way.brave · brave | Orta5,3 | — | %0,7 | 3 May 2017 |
19İzleyin | CVE-2016-9473İstismar yok | Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trbrave · browser · CWE-451 | Orta4,7 | — | %1,9 | 27 Mar 2017 |
18İzleyin | CVE-2017-1000461İstismar yok | Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting bbrave · browser · CWE-732 | Orta4,7 | — | %1,0 | 3 Oca 2018 |
17İzleyin | CVE-2018-1000815İstismar yok | Brave Software Inc.brave · brave · CWE-20 | Orta4,3 | — | %1,1 | 20 Ara 2018 |
17İzleyin | CVE-2023-28360İstismar yok | An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file tbrave · brave · CWE-223 | Orta4,3 | — | %0,8 | 11 May 2023 |
- CVE-2016-1071834İzleyin
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.
YüksekCVSS 7,5Kavram kanıtıEPSS %12brave · brave browser3 Nis 2018
- CVE-2021-4588431İzleyin
In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled,
YüksekCVSS 7,5İstismar yokEPSS %3brave · brave27 Ara 2021
- CVE-2024-3740630İzleyin
In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to dom
YüksekCVSS 7,5İstismar yokEPSS %0brave · android browser18 Eyl 2024
- CVE-2017-1825627İzleyin
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaS
OrtaCVSS 6,5Kavram kanıtıEPSS %5brave · brave browser3 Nis 2018
- CVE-2021-2291726İzleyin
Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowi
OrtaCVSS 6,5İstismar yokEPSS %1brave · browser12 Tem 2021
- CVE-2017-845826İzleyin
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://safe.example.com@unsafe.example.com/ is displayed without a clear
OrtaCVSS 6,5İstismar yokEPSS %1brave · brave3 May 2017
- CVE-2022-4793226İzleyin
Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns
OrtaCVSS 6,5İstismar yokEPSS %1brave · brave24 Ara 2022
- CVE-2022-4793426İzleyin
Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file tha
OrtaCVSS 6,5İstismar yokEPSS %1brave · brave24 Ara 2022
- CVE-2022-4793326İzleyin
Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme.
OrtaCVSS 6,5İstismar yokEPSS %1brave · brave24 Ara 2022
- CVE-2018-1079826İzleyin
A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux).
OrtaCVSS 6,5İstismar yokEPSS %1brave · brave8 May 2018
- CVE-2018-1079926İzleyin
A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux).
OrtaCVSS 6,5İstismar yokEPSS %1brave · brave8 May 2018
- CVE-2021-2291624İzleyin
In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblock
OrtaCVSS 5,9İstismar yokEPSS %3brave · brave12 Tem 2021
- CVE-2021-2292924İzleyin
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps o
OrtaCVSS 6,1İstismar yokEPSS %1brave · brave31 Ağu 2021
- CVE-2023-2279824İzleyin
Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websi
OrtaCVSS 6,1İstismar yokEPSS %0brave · adblock-lists9 Şub 2023
- CVE-2023-5226324İzleyin
Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect.
OrtaCVSS 6,1İstismar yokEPSS %0brave · browser30 Ara 2023
- CVE-2023-2836424İzleyin
An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned
OrtaCVSS 6,1İstismar yokEPSS %0brave · browser30 Haz 2023
- CVE-2022-3033422İzleyin
Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers.
OrtaCVSS 5,3İstismar yokEPSS %3brave · brave7 May 2022
- CVE-2021-2132322İzleyin
Regression in DNS leakage from Tor windows
OrtaCVSS 5,3İstismar yokEPSS %2brave · brave23 Şub 2021
- CVE-2020-827622İzleyin
The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the use
OrtaCVSS 5,5İstismar yokEPSS %0brave · brave9 Kas 2020
- CVE-2017-845921İzleyin
Brave 0.12.4 has a Status Bar Obfuscation issue in which a redirection target is shown in a possibly unexpected way.
OrtaCVSS 5,3İstismar yokEPSS %1brave · brave3 May 2017
- CVE-2016-947319İzleyin
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to tr
OrtaCVSS 4,7İstismar yokEPSS %2brave · browser27 Mar 2017
- CVE-2017-100046118İzleyin
Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting b
OrtaCVSS 4,7İstismar yokEPSS %1brave · browser3 Oca 2018
- CVE-2018-100081517İzleyin
Brave Software Inc.
OrtaCVSS 4,3İstismar yokEPSS %1brave · brave20 Ara 2018
- CVE-2023-2836017İzleyin
An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file t
OrtaCVSS 4,3İstismar yokEPSS %1brave · brave11 May 2023