cbcvebase.

Qutebrowser vulnerabilities

4 known vulnerabilities affecting qutebrowser/qutebrowser.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2021-41146P3HIGHCVSS 8.8≤ 1.7.0≥ 2.0.0, < 2.4.0+1 more2021-10-21
CVE-2021-41146 [HIGH] CWE-77 CVE-2021-41146: qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead to execution of qutebrowser commands, which in turn allows arbitrary code e
ghsanvdosv
CVE-2018-10895P3HIGHCVSS 8.8fixed in 1.4.12018-07-12
CVE-2018-10895 [HIGH] CWE-352 CVE-2018-10895: qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows webs qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.
ghsanvdosv
CVE-2018-1000559P4MEDIUMCVSS 6.1≥ 0.11.0, < 1.3.32018-06-26
CVE-2018-1000559 [MEDIUM] CWE-79 CVE-2018-1000559: qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cros qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the victim must open a page with
ghsanvdosv
CVE-2020-11054P4LOWCVSS 3.5fixed in 1.11.12020-05-07
CVE-2020-11054 [LOW] CWE-684 CVE-2020-11054: In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly displayed as green (colors.statusbar.u
ghsanvdosv
Qutebrowser vulnerabilities | cvebase