Fenrir maintains a small portfolio of web browsers and content-delivery applications, including products such as Grani, Sleipnir, and DarkSky RSS Bar, that serve niche and localized user bases. The vulnerabilities affecting these products cluster around web-application input-handling issues, notably cross-site scripting flaws in page-generation routines, reflecting the attack surface inherent to browser and feed-rendering engines. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fenrir over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7831MEDIUM Sleipnir 4 Black Edition for Mac 4.5.3 and earlier and Sleipnir 4 for Mac 4.5.3 and earlier (Mac App Store) may allow a remote attacker to spoof the URL display via a specially cra | Jun 9, 2017 | 6.1 | 22 | NO | NO |
CVE-2012-2649MEDIUM The Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allow remote attackers to execute arbitrary Java metho | Aug 8, 2012 | 6.8 | 22 | NO | NO |
CVE-2010-3164MEDIUM Untrusted search path vulnerability in Fenrir Sleipnir 2.9.4 and earlier and Grani 4.3 and earlier allows local users to gain privileges via a Trojan horse executable file in the c | Oct 25, 2010 | 6.9 | 21 | NO | NO |
CVE-2010-3163MEDIUM Untrusted search path vulnerability in Fenrir Sleipnir before 2.9.5 and Grani before 4.4 allows local users to gain privileges via a Trojan horse DLL in the current working directo | Oct 25, 2010 | 6.9 | 21 | NO | NO |
CVE-2010-2420MEDIUM Multiple unspecified vulnerabilities in Fenrir Inc. ActiveGeckoBrowser 1.0.0 and 1.0.5 alpha, a module for the Sleipnir web browser, allow remote attackers to cause a denial of ser | Jun 22, 2010 | 6.8 | 21 | NO | NO |
CVE-2010-3918MEDIUM Fenrir Sleipnir 2.9.6 and earlier does not prevent interaction between web script and the clipboard, which allows remote attackers to read or modify the clipboard contents via a cr | Dec 10, 2010 | 5.8 | 20 | NO | NO |
CVE-2013-2304MEDIUM The Sleipnir Mobile application 2.8.0 and earlier and Sleipnir Mobile Black Edition application 2.8.0 and earlier for Android allow remote attackers to load arbitrary Extension API | Apr 16, 2013 | 5.8 | 19 | NO | NO |
CVE-2010-3919MEDIUM Fenrir Grani 4.5 and earlier does not prevent interaction between web script and the clipboard, which allows remote attackers to read or modify the clipboard contents via a crafted | Dec 10, 2010 | 5.8 | 19 | NO | NO |
CVE-2007-0705HIGH Cross-zone scripting vulnerability in Sleipnir 2.49 and earlier, and Portable Sleipnir 2.45 and earlier, allows remote attackers to bypass Web content zone restrictions via certain | Feb 4, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-0706HIGH Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attacke | Feb 4, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fenrir.
Media articles that mention a CVE ID that affects a product developed by Fenrir — matched by CVE ID, not by vendor name.