Yandex N.V.

First CVE: Oct 26, 2016Active for: 10 years
37
CVEs Published
More CVEs Published than 51% of tracked CNAs
4.1
Avg CVEs / Year
More Avg CVEs / Year than 29% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 59% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Yandex N.V. as a CNA, 64.9% affect products that Yandex N.V. develops as a vendor.

64.9%
35.1%
Self-reported: 24Third-party: 13

Of all the CVEs published that affect products developed by Yandex N.V., 77.4% are self-published by Yandex N.V. as a CNA.

77.4%
22.6%
Self-published: 24Published by other CNAs: 7

Trends Over Time

The number and severity of CVEs published by Yandex N.V. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2016
9 years ago
Most Recent CVE
Jun 2, 2026
52 days ago

Top CVEs

All CVEs published by Yandex N.V. as a CNA, regardless of affected vendor or product.

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.
Aug 15, 20199.830NONO
In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
Dec 30, 20199.829NONO
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
Aug 15, 20199.829NONO
Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory loca
Dec 23, 20229.128NONO
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through
Jun 15, 20227.826NONO
LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauth
Jun 2, 20265.325NONO
A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682
May 30, 20259.825NONO
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through
Aug 17, 20217.825NONO
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery At
Aug 15, 20198.825NONO
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resourc
Oct 26, 20167.325NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA37 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local10 (27.0%)
Network27 (73.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (97.3%)
High1 (2.7%)
Unknown0 (0.0%)
User Interaction
None26 (70.3%)
Unknown0 (0.0%)
Required11 (29.7%)
Privileges Required
Low10 (27.0%)
High0 (0.0%)
None27 (73.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Yandex N.V. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Yandex N.V. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs