CVE-2016-8506

XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.
References
Link Resource
https://browser.yandex.com/security/changelogs/ Release Notes Vendor Advisory
http://www.securityfocus.com/bid/93927 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:yandex:yandex_browser:15.4.2272.3429:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:15.2.2214.3645:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:15.12.1.6475:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:15.6.2311.5029:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:16.2.0.3539:*:*:*:*:*:*:*
cpe:2.3:a:yandex:yandex_browser:15.12.0.6151:*:*:*:*:*:*:*

Information

Published : 2016-10-26 11:59

Updated : 2016-12-02 15:48


NVD link : CVE-2016-8506

Mitre link : CVE-2016-8506


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

yandex

  • yandex_browser