Vulnerability Details CVE-2017-7325
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-7325
-
cpe:2.3:a:yandex:yandex_browser:-
-
cpe:2.3:a:yandex:yandex_browser:15.10
-
cpe:2.3:a:yandex:yandex_browser:15.10.2454.3845
-
cpe:2.3:a:yandex:yandex_browser:15.12
-
cpe:2.3:a:yandex:yandex_browser:15.12.0
-
cpe:2.3:a:yandex:yandex_browser:15.12.0.6151
-
cpe:2.3:a:yandex:yandex_browser:15.12.1.6475
-
cpe:2.3:a:yandex:yandex_browser:15.2.2214.3645
-
cpe:2.3:a:yandex:yandex_browser:15.4.2272.3429
-
cpe:2.3:a:yandex:yandex_browser:15.6.2311.5029
-
cpe:2.3:a:yandex:yandex_browser:16.2
-
cpe:2.3:a:yandex:yandex_browser:16.2.0.3539
-
cpe:2.3:a:yandex:yandex_browser:16.4.0.9335
-
cpe:2.3:a:yandex:yandex_browser:16.4.0.9404
-
cpe:2.3:a:yandex:yandex_browser:16.6
-
cpe:2.3:a:yandex:yandex_browser:16.6.0.8810
-
cpe:2.3:a:yandex:yandex_browser:16.6.1.30165
-
cpe:2.3:a:yandex:yandex_browser:16.6.1.9652
-
cpe:2.3:a:yandex:yandex_browser:16.7.0
-
cpe:2.3:a:yandex:yandex_browser:16.7.0.2777
-
cpe:2.3:a:yandex:yandex_browser:16.7.0.3342
-
cpe:2.3:a:yandex:yandex_browser:16.7.1.20808
-
cpe:2.3:a:yandex:yandex_browser:16.7.1.2912
-
cpe:2.3:a:yandex:yandex_browser:16.9