« Volver al listado

CVE-2016-8501

Estado: ModificadaMedia (5.3)—

Security WiFi bypass in Yandex Browser from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected wi-fi networks despite of special security mechanism is enabled.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-8501",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "browser-security@yandex-team.ru",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Yandex Browser for desktop Versions from 15.10 to 15.12",
          "versions": [
            {
              "status": "affected",
              "version": "Yandex Browser for desktop Versions from 15.10 to 15.12"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-10-26T18:59:00.173",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/93920",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "browser-security@yandex-team.ru"
    },
    {
      "url": "https://browser.yandex.com/security/changelogs/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "browser-security@yandex-team.ru"
    },
    {
      "url": "http://www.securityfocus.com/bid/93920",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://browser.yandex.com/security/changelogs/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Security WiFi bypass in Yandex Browser from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected wi-fi networks despite of special security mechanism is enabled."
    },
    {
      "lang": "es",
      "value": "Elusión de Security WiFi en Yandex Browser en versiones desde 15.10 hasta 15.12 permite a atacantes remotos espiar el tráfico en redes Wi-Fi abiertas o protegidas por WEP a pesar de que los mecanismos especiales de seguridad estén activos."
    }
  ],
  "lastModified": "2026-06-17T00:54:27.650",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:15.10.2454.3845:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FAEA553-A29E-4C0D-A27D-D1D8E1C2C2FD"
            },
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:15.12.0.6151:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "728028D5-E37F-41A2-BDCF-1F700DB1C313"
            },
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:15.12.1.6475:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02ADC9FA-45D1-4D84-B330-E60D6FCF3680"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "browser-security@yandex-team.ru"
}