Vulnerabilities > Snowhaze

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2019-18949 Incorrect Authorization vulnerability in Snowhaze
SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.
network
low complexity
snowhaze CWE-863
7.5