CVE-2016-8506

XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.
References
Link Resource
http://www.securityfocus.com/bid/93927 Third Party Advisory VDB Entry
https://browser.yandex.com/security/changelogs/ Release Notes Vendor Advisory
http://www.securityfocus.com/bid/93927 Third Party Advisory VDB Entry
https://browser.yandex.com/security/changelogs/ Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:yandex:yandex_browser:15.2.2214.3645:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:15.4.2272.3429:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:15.6.2311.5029:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:15.12.0.6151:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:15.12.1.6475:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:16.2.0.3539:*:*:*:*:*:*:*

History

21 Nov 2024, 02:59

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/93927 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/93927 - Third Party Advisory, VDB Entry
References () https://browser.yandex.com/security/changelogs/ - Release Notes, Vendor Advisory () https://browser.yandex.com/security/changelogs/ - Release Notes, Vendor Advisory

Information

Published : 2016-10-26 18:59

Updated : 2024-11-21 02:59


NVD link : CVE-2016-8506

Mitre link : CVE-2016-8506

CVE.ORG link : CVE-2016-8506


JSON object : View

Products Affected

yandex

  • yandex_browser
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')