Skip to main content

Vendor archive

netsurf-browser CVEs

Beta · best-effort

8 CVEs tagged to vendor netsurf-browser0 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-45663

Published Nov 3, 2025

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-29699

Published Nov 3, 2025

NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
25.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-51317

Published Nov 3, 2025

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7507

Published Feb 18, 2020

libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7505

Published Feb 18, 2020

Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or pos…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7506

Published Feb 18, 2020

The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7508

Published Feb 12, 2020

Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or po…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1