Vulnerabilities > Yandex
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-06-15 | CVE-2021-25261 | Link Following vulnerability in Yandex Browser Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process. | 7.2 |
2022-06-15 | CVE-2022-28225 | Link Following vulnerability in Yandex Browser Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process. | 7.2 |
2022-06-15 | CVE-2022-28226 | Incorrect Permission Assignment for Critical Resource vulnerability in Yandex Browser Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process. | 7.2 |
2022-03-14 | CVE-2021-42387 | Out-of-bounds Read vulnerability in multiple products Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. | 8.1 |
2022-03-14 | CVE-2021-42388 | Out-of-bounds Read vulnerability in multiple products Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. | 8.1 |
2022-03-14 | CVE-2021-42389 | Divide By Zero vulnerability in Yandex Clickhouse Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. | 4.0 |
2022-03-14 | CVE-2021-42390 | Divide By Zero vulnerability in Yandex Clickhouse Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. | 4.0 |
2022-03-14 | CVE-2021-42391 | Divide By Zero vulnerability in Yandex Clickhouse Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. | 5.0 |
2022-03-14 | CVE-2021-43304 | Out-of-bounds Write vulnerability in multiple products Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. | 8.8 |
2022-03-14 | CVE-2021-43305 | Out-of-bounds Write vulnerability in multiple products Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. | 8.8 |