Maxthon Browser vulnerabilities
5 known vulnerabilities affecting maxthon/maxthon_browser.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2019-16647P1HIGHCVSS 7.2ExploitedRansomware≥ 5.1.0, ≤ 5.2.72019-10-29
CVE-2019-16647 [HIGH] CWE-428 CVE-2019-16647: Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
nvd
CVE-2008-3667P3MEDIUMCVSS 6.8PoC≤ 2.0v1.1.39+3 more2008-08-13
CVE-2008-3667 [MEDIUM] CWE-119 CVE-2008-3667: Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute ar
Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header.
nvd
CVE-2010-5246P4MEDIUMCVSS 6.9v1.6.7.35v2.5.152012-09-07
CVE-2010-5246 [MEDIUM] CVE-2010-5246: Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local us
Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan horse (1) RSRC32.dll or (2) dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .html file. NOTE: the provenance of this information is unknown; the details are obtained solely fro
nvd
CVE-2009-3006P4MEDIUMCVSS 4.3v2.5.3.802009-08-28
CVE-2009-3006 [MEDIUM] CVE-2009-3006: Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open w
Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.
nvd
CVE-2009-3018P4MEDIUMCVSS 4.3v3.0.0.1452009-08-31
CVE-2009-3018 [MEDIUM] CWE-79 CVE-2009-3018: Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in
Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the cont
nvd