8.2
CVE-2021-25254
- EPSS 0.46%
- Veröffentlicht 21.05.2025 06:58:00
- Zuletzt bearbeitet 10.06.2025 15:51:27
- Quelle browser-security@yandex-team.r
- CVE-Watchlists
- Unerledigt
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yandex ≫ Yandex Browser SwEditionlite SwPlatformandroid Version < 21.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.364 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| browser-security@yandex-team.ru | 8.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-116 Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
https://yandex.com/bugbounty/i/hall-of-fame-browser/