Vulnerability Description
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yandex | Yandex Browser | < 17.1.1.227 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96514Third Party AdvisoryVDB Entry
- https://yandex.com/blog/security-changelogs/fixed-in-version-17-1Vendor Advisory
- http://www.securityfocus.com/bid/96514Third Party AdvisoryVDB Entry
- https://yandex.com/blog/security-changelogs/fixed-in-version-17-1Vendor Advisory
FAQ
What is CVE-2016-8508?
CVE-2016-8508 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for pre...
How severe is CVE-2016-8508?
CVE-2016-8508 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8508?
Check the references section above for vendor advisories and patch information. Affected products include: Yandex Yandex Browser.