« Back to list

CVE-2016-8506

Status: ModifiedMedium (6.1)—

XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2016-8506",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "browser-security@yandex-team.ru",
      "affectedData": [
        {
          "vendor": "Yandex N.V.",
          "product": "Yandex Browser for desktop",
          "versions": [
            {
              "status": "affected",
              "version": "15.12 to 16.2 for OSx and Linux"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-10-26T18:59:08.533",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/93927",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "browser-security@yandex-team.ru"
    },
    {
      "url": "https://browser.yandex.com/security/changelogs/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "browser-security@yandex-team.ru"
    },
    {
      "url": "http://www.securityfocus.com/bid/93927",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://browser.yandex.com/security/changelogs/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code."
    },
    {
      "lang": "es",
      "value": "XSS en Yandex Browser Translator en navegador Yandex para escritorio para versiones desde 15.12 hasta 16.2 podría ser usado por atacantes remotos para una evaluación arbitraria de un código javascript."
    }
  ],
  "lastModified": "2026-06-17T00:54:28.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:15.2.2214.3645:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85BD2680-01D4-4B05-9358-EB550E91A9FF"
            },
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:15.4.2272.3429:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00F9C181-CEDC-4E2C-8776-31C56B950D41"
            },
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:15.6.2311.5029:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8D32042-ECD2-4D04-ADFB-4C45F22E7977"
            },
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:15.12.0.6151:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "728028D5-E37F-41A2-BDCF-1F700DB1C313"
            },
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:15.12.1.6475:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02ADC9FA-45D1-4D84-B330-E60D6FCF3680"
            },
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:16.2.0.3539:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A340C337-7203-4817-AE86-6B767C03B1F9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "browser-security@yandex-team.ru"
}