NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11031 | CVE-2011-4678 | The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which allows remote attackers to enumerate user accounts via a series of requests. | 2 | 5 | Medium | 2017-01-07 | 2011-12-08 | View | |
| 11032 | CVE-2011-4679 | vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report. | 2 | 4 | Medium | 2017-01-07 | 2012-03-07 | View | |
| 11033 | CVE-2011-4680 | Multiple cross-site scripting (XSS) vulnerabilities in the customer portal in vtiger CRM before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2012-03-07 | View | |
| 11034 | CVE-2011-4681 | Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names of different top-level domains, which allows remote attackers to bypass the Same Origin Policy by leveraging access to a different domain name in the same top-level domain, as demonstrated by the .no or .uk domain. | 2 | 5 | Medium | 2017-01-07 | 2012-03-06 | View | |
| 11035 | CVE-2011-4682 | The JavaScript engine in Opera before 11.60 does not properly implement the in operator, which allows remote attackers to bypass the Same Origin Policy via vectors related to variables on different web sites. | 2 | 6.4 | Medium | 2017-01-07 | 2012-03-06 | View |
Page 2207 of 17672, showing 5 records out of 88360 total, starting on record 11031, ending on 11035