Uzbl is a lightweight, keyboard-driven web browser designed for minimalist and power-user workflows, with a narrow product scope centered on the core browser application. Its observed vulnerability exposures cluster around information-disclosure and code-injection issues, reflecting the inherent parsing and execution risks of a rendering engine. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uzbl over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2809MEDIUM The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute | Aug 19, 2010 | 6.8 | 31 | NO | YES |
CVE-2010-0011HIGH The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript | Feb 25, 2010 | 7.5 | 20 | NO | NO |
CVE-2012-0843MEDIUM uzbl: Information disclosure via world-readable cookies storage file | Nov 19, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uzbl.
Media articles that mention a CVE ID that affects a product developed by Uzbl — matched by CVE ID, not by vendor name.