Vulnerability Description
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yandex | Yandex Browser | <= 16.6.1.30165 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/93924Third Party AdvisoryVDB Entry
- https://browser.yandex.com/security/changelogs/Release NotesVendor Advisory
- http://www.securityfocus.com/bid/93924Third Party AdvisoryVDB Entry
- https://browser.yandex.com/security/changelogs/Release NotesVendor Advisory
FAQ
What is CVE-2016-8504?
CVE-2016-8504 is a vulnerability with a CVSS score of 4.3 (MEDIUM). CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.
How severe is CVE-2016-8504?
CVE-2016-8504 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8504?
Check the references section above for vendor advisories and patch information. Affected products include: Yandex Yandex Browser.