Lunascape is a multi-engine web browser available on desktop and mobile platforms, with its vulnerability exposure centered on information-disclosure and sensitive-data handling issues. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lunascape over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3927MEDIUM Untrusted search path vulnerability in Lunascape before 6.4.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | Jan 24, 2011 | 6.9 | 21 | NO | NO |
CVE-2011-0452MEDIUM Untrusted search path vulnerability in the script function in Lunascape before 6.4.3 allows local users to gain privileges via a Trojan horse executable file in the current working | Feb 24, 2011 | 6.2 | 19 | NO | NO |
CVE-2012-1249MEDIUM The iLunascape application 1.0.4.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive stored information via a | May 21, 2012 | 5.0 | 18 | NO | NO |
CVE-2009-3005MEDIUM Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as | Aug 28, 2009 | 4.3 | 15 | NO | NO |
CVE-2007-2335MEDIUM Cross-site scripting (XSS) vulnerability in the RSS feed reader functionality in Lunascape 4.1.3 build2 and earlier allows remote attackers to inject arbitrary web script or HTML v | Apr 27, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lunascape.
Media articles that mention a CVE ID that affects a product developed by Lunascape — matched by CVE ID, not by vendor name.