Security changelogs

Fixed in version 17.1
27 February, 09:10

CVE-2016-8508: Oleynik Yaroslav

Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnigns in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.

No comments
CVE-2016-8508
Fixed in version 16.10
27 February, 09:00

CVE-2016-8507: mohaab007

Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site. 

No comments
CVE-2016-8507
Fixed in version 16.9
26 October 2016, 09:20

CVE-2016-8503: Evgeny Sukhov

Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7.0 to 16.9.0 could be used by a remote attacker for brute-forcing passwords from important web-resource (without opportunity of getting login or important resource's address) with special JavaScript-code.

No comments
Fixed in version 16.6
26 October 2016, 09:10

CVE-2016-8504: Ziyahan Albeniz

CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.

CVE-2016-8505: Jouko

XSS in Yandex Browser's BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary JavaScript-code.

No comments
CVE-2016-8504
Fixed in version 16.2
26 October 2016, 09:05

CVE-2016-8502: Evgeny Sukhov

Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2.0 could be used by a remote attacker for brute forcing passwords from important web-resource (without opportunity of getting login or important resource's address) with special JavaScript-code.

CVE-2016-8506: Thereissuchname

XSS in Yandex Browser's Translator in Yandex Browser for desktop for versions from 15.12.0 to 16.2.0 could be used by a remote attacker for evaluation arbitrary JavaScript-code.

No comments
CVE-2016-8502,CVE-2016-8506
Fixed in version 15.12
26 October 2016, 09:00

CVE-2016-8501: Vladimir Dubrovin

Security WiFi bypass in Yandex Browser for desktop from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected Wi-Fi networks despite of special security mechanism is enabled.

No comments
CVE-2016-8501