Yandex kayıtları
yandex üreticisine ait 31 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %3,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-254 7PK - Security Features3
- CWE-426 Untrusted Search Path3
- CWE-116 Improper Encoding or Escaping of Output2
- CWE-20 Improper Input Validation2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
31 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2021-25255İstismar yok | Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.yandex · yandex browser · CWE-20 | Yüksek8,3 | — | %0,8 | 21 May 2025 |
33İzleyin | CVE-2024-6473Kavram kanıtı | DLL Hijacking in Yandex Browseryandex · yandex browser · CWE-426 | Yüksek8,4 | — | %0,7 | 3 Eyl 2024 |
33İzleyin | CVE-2024-12168İstismar yok | DLL Hijacking in Yandex Telemostyandex · yandex telemost · CWE-426 | Yüksek8,4 | — | %0,2 | 2 Haz 2025 |
32İzleyin | CVE-2016-10666İstismar yok | tomita-parser is a Node wrapper for Yandex Tomita Parser tomita-parser downloads binary resources over HTTP, which leaves it vulnerable to Myandex · tomita-parser · CWE-311 | Yüksek8,1 | — | %1,7 | 29 May 2018 |
32İzleyin | CVE-2021-25254İstismar yok | Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.yandex · yandex browser · CWE-116 | Yüksek8,2 | — | %0,5 | 21 May 2025 |
31İzleyin | CVE-2017-7327İstismar yok | Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dllyandex · yandex browser · CWE-426 | Yüksek7,8 | — | %1,4 | 19 Oca 2018 |
31İzleyin | CVE-2021-25261İstismar yok | Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitaryyandex · yandex browser · CWE-59 | Yüksek7,8 | — | %0,5 | 15 Haz 2022 |
31İzleyin | CVE-2022-28225İstismar yok | Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitaryyandex · yandex browser · CWE-59 | Yüksek7,8 | — | %0,5 | 15 Haz 2022 |
31İzleyin | CVE-2021-25263İstismar yok | Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitaryyandex · yandex browser · CWE-732 | Yüksek7,8 | — | %0,4 | 17 Ağu 2021 |
31İzleyin | CVE-2022-28226İstismar yok | Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitaryyandex · yandex browser · CWE-668 | Yüksek7,8 | — | %0,4 | 15 Haz 2022 |
31İzleyin | CVE-2023-29749İstismar yok | An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the yandex · navigator | Yüksek7,8 | — | %0,4 | 9 Haz 2023 |
30İzleyin | CVE-2017-7325İstismar yok | Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.yandex · yandex browser · CWE-20 | Yüksek7,5 | — | %1,1 | 19 Oca 2018 |
30İzleyin | CVE-2017-7326İstismar yok | Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via ayandex · yandex browser · CWE-362 | Yüksek7,5 | — | %0,8 | 19 Oca 2018 |
29İzleyin | CVE-2016-8502İstismar yok | Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-fyandex · yandex browser · CWE-254 | Yüksek7,3 | — | %1,0 | 26 Eki 2016 |
29İzleyin | CVE-2016-8503İstismar yok | Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcyandex · yandex browser · CWE-254 | Yüksek7,3 | — | %1,0 | 26 Eki 2016 |
29İzleyin | CVE-2020-27969İstismar yok | Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofingyandex · yandex browser · CWE-346 | Yüksek7,3 | — | %0,5 | 13 Eyl 2021 |
29İzleyin | CVE-2023-26226İstismar yok | A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682yandex · yandex browser · CWE-416 | Yüksek7,4 | — | %0,4 | 30 May 2025 |
29İzleyin | CVE-2025-5471İstismar yok | Dylib Hijacking in Yandex Telemostyandex · yandex telemost · CWE-427 | Yüksek7,3 | — | %0,2 | 9 Ara 2025 |
27İzleyin | CVE-2021-25262İstismar yok | Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.yandex · yandex browser · CWE-116 | Orta6,9 | — | %0,4 | 21 May 2025 |
26İzleyin | CVE-2016-8508İstismar yok | Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special yandex · yandex browser · CWE-254 | Orta6,5 | — | %1,6 | 1 Mar 2017 |
26İzleyin | CVE-2016-8507İstismar yok | Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiyandex · yandex browser · CWE-200 | Orta6,5 | — | %1,5 | 1 Mar 2017 |
24İzleyin | CVE-2016-8506İstismar yok | XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluatiyandex · yandex browser · CWE-79 | Orta6,1 | — | %0,9 | 26 Eki 2016 |
24İzleyin | CVE-2016-8505İstismar yok | XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6.yandex · yandex.browser · CWE-79 | Orta6,1 | — | %0,9 | 26 Eki 2016 |
22İzleyin | CVE-2023-29751İstismar yok | An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the Syandex · navigator · CWE-346 | Orta5,5 | — | %0,2 | 9 Haz 2023 |
21İzleyin | CVE-2020-27970İstismar yok | Yandex Browser before 20.10.0 allows remote attackers to spoof the address baryandex · yandex browser · CWE-290 | Orta5,3 | — | %1,3 | 13 Eyl 2021 |
- CVE-2021-2525533İzleyin
Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.
YüksekCVSS 8,3İstismar yokEPSS %1yandex · yandex browser21 May 2025
- CVE-2024-647333İzleyin
DLL Hijacking in Yandex Browser
YüksekCVSS 8,4Kavram kanıtıEPSS %1yandex · yandex browser3 Eyl 2024
- CVE-2024-1216833İzleyin
DLL Hijacking in Yandex Telemost
YüksekCVSS 8,4İstismar yokEPSS %0yandex · yandex telemost2 Haz 2025
- CVE-2016-1066632İzleyin
tomita-parser is a Node wrapper for Yandex Tomita Parser tomita-parser downloads binary resources over HTTP, which leaves it vulnerable to M
YüksekCVSS 8,1İstismar yokEPSS %2yandex · tomita-parser29 May 2018
- CVE-2021-2525432İzleyin
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
YüksekCVSS 8,2İstismar yokEPSS %1yandex · yandex browser21 May 2025
- CVE-2017-732731İzleyin
Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll
YüksekCVSS 7,8İstismar yokEPSS %1yandex · yandex browser19 Oca 2018
- CVE-2021-2526131İzleyin
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary
YüksekCVSS 7,8İstismar yokEPSS %0yandex · yandex browser15 Haz 2022
- CVE-2022-2822531İzleyin
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary
YüksekCVSS 7,8İstismar yokEPSS %0yandex · yandex browser15 Haz 2022
- CVE-2021-2526331İzleyin
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary
YüksekCVSS 7,8İstismar yokEPSS %0yandex · yandex browser17 Ağu 2021
- CVE-2022-2822631İzleyin
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary
YüksekCVSS 7,8İstismar yokEPSS %0yandex · yandex browser15 Haz 2022
- CVE-2023-2974931İzleyin
An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the
YüksekCVSS 7,8İstismar yokEPSS %0yandex · navigator9 Haz 2023
- CVE-2017-732530İzleyin
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
YüksekCVSS 7,5İstismar yokEPSS %1yandex · yandex browser19 Oca 2018
- CVE-2017-732630İzleyin
Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via a
YüksekCVSS 7,5İstismar yokEPSS %1yandex · yandex browser19 Oca 2018
- CVE-2016-850229İzleyin
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-f
YüksekCVSS 7,3İstismar yokEPSS %1yandex · yandex browser26 Eki 2016
- CVE-2016-850329İzleyin
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forc
YüksekCVSS 7,3İstismar yokEPSS %1yandex · yandex browser26 Eki 2016
- CVE-2020-2796929İzleyin
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
YüksekCVSS 7,3İstismar yokEPSS %1yandex · yandex browser13 Eyl 2021
- CVE-2023-2622629İzleyin
A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682
YüksekCVSS 7,4İstismar yokEPSS %0yandex · yandex browser30 May 2025
- CVE-2025-547129İzleyin
Dylib Hijacking in Yandex Telemost
YüksekCVSS 7,3İstismar yokEPSS %0yandex · yandex telemost9 Ara 2025
- CVE-2021-2526227İzleyin
Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.
OrtaCVSS 6,9İstismar yokEPSS %0yandex · yandex browser21 May 2025
- CVE-2016-850826İzleyin
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special
OrtaCVSS 6,5İstismar yokEPSS %2yandex · yandex browser1 Mar 2017
- CVE-2016-850726İzleyin
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initi
OrtaCVSS 6,5İstismar yokEPSS %2yandex · yandex browser1 Mar 2017
- CVE-2016-850624İzleyin
XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluati
OrtaCVSS 6,1İstismar yokEPSS %1yandex · yandex browser26 Eki 2016
- CVE-2016-850524İzleyin
XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6.
OrtaCVSS 6,1İstismar yokEPSS %1yandex · yandex.browser26 Eki 2016
- CVE-2023-2975122İzleyin
An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the S
OrtaCVSS 5,5İstismar yokEPSS %0yandex · navigator9 Haz 2023
- CVE-2020-2797021İzleyin
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
OrtaCVSS 5,3İstismar yokEPSS %1yandex · yandex browser13 Eyl 2021