CVE-2016-8502: High severity yandex browser vulnerability
Published Oct 26, 2016
·Updated
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
Affected Software
3 affected components
Yandex Yandex Browser=15.12.0.6151
Yandex Yandex Browser=15.12.1.6475
Yandex Yandex Browser=16.2.0.3539
Event History
Oct 26, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8502?
CVE-2016-8502 is considered a high-severity vulnerability that could allow remote attackers to perform brute-force attacks on user passwords.
2
How do I fix CVE-2016-8502?
To mitigate CVE-2016-8502, it is recommended to update Yandex Browser to the latest version beyond 16.2.
3
Which versions of Yandex Browser are affected by CVE-2016-8502?
CVE-2016-8502 affects Yandex Browser versions 15.12.0 to 16.2.
4
Can CVE-2016-8502 be exploited without user interaction?
Yes, CVE-2016-8502 can be exploited by a remote attacker without requiring any user interaction.
5
What type of attack does CVE-2016-8502 facilitate?
CVE-2016-8502 facilitates brute-force attacks on important web resources using specially crafted JavaScript.