This page aggregates publicly disclosed CVE and security risk information related to arora-browser, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2011-3367 | Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text. | [email protected] | 5.0 | 0.13% | 2011-11-29 | 2026-04-29 |
| CVE-2010-1100 | Integer overflow in Arora allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25. | [email protected] | 5.0 | 0.22% | 2010-03-24 | 2026-04-29 |