NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11035 | CVE-2011-4682 | The JavaScript engine in Opera before 11.60 does not properly implement the in operator, which allows remote attackers to bypass the Same Origin Policy via vectors related to variables on different web sites. | 2 | 6.4 | Medium | 2017-01-07 | 2012-03-06 | View | |
| 11034 | CVE-2011-4681 | Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names of different top-level domains, which allows remote attackers to bypass the Same Origin Policy by leveraging access to a different domain name in the same top-level domain, as demonstrated by the .no or .uk domain. | 2 | 5 | Medium | 2017-01-07 | 2012-03-06 | View | |
| 11033 | CVE-2011-4680 | Multiple cross-site scripting (XSS) vulnerabilities in the customer portal in vtiger CRM before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2012-03-07 | View | |
| 11032 | CVE-2011-4679 | vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report. | 2 | 4 | Medium | 2017-01-07 | 2012-03-07 | View | |
| 11031 | CVE-2011-4678 | The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which allows remote attackers to enumerate user accounts via a series of requests. | 2 | 5 | Medium | 2017-01-07 | 2011-12-08 | View |
Page 15466 of 17672, showing 5 records out of 88360 total, starting on record 77326, ending on 77330