NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11035  CVE-2011-4682  The JavaScript engine in Opera before 11.60 does not properly implement the in operator, which allows remote attackers to bypass the Same Origin Policy via vectors related to variables on different web sites.    6.4  Medium  2017-01-07  2012-03-06  View
11034  CVE-2011-4681  Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names of different top-level domains, which allows remote attackers to bypass the Same Origin Policy by leveraging access to a different domain name in the same top-level domain, as demonstrated by the .no or .uk domain.    Medium  2017-01-07  2012-03-06  View
11033  CVE-2011-4680  Multiple cross-site scripting (XSS) vulnerabilities in the customer portal in vtiger CRM before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-07  2012-03-07  View
11032  CVE-2011-4679  vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.    Medium  2017-01-07  2012-03-07  View
11031  CVE-2011-4678  The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which allows remote attackers to enumerate user accounts via a series of requests.    Medium  2017-01-07  2011-12-08  View

Page 15466 of 17672, showing 5 records out of 88360 total, starting on record 77326, ending on 77330

Actions