Show filters
331 Total Results
Displaying 21-30 of 331
Sort by:
Attacker Value
Unknown
CVE-2016-7152
Disclosure Date: September 06, 2016 (last updated November 25, 2024)
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
0
Attacker Value
Unknown
CVE-2016-7153
Disclosure Date: September 06, 2016 (last updated November 25, 2024)
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
0
Attacker Value
Unknown
CVE-2016-5101
Disclosure Date: June 29, 2016 (last updated November 25, 2024)
Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted e-mail message.
0
Attacker Value
Unknown
CVE-2015-5515
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.
0
Attacker Value
Unknown
CVE-2015-4000
Disclosure Date: May 21, 2015 (last updated October 23, 2024)
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
0
Attacker Value
Unknown
CVE-2014-1870
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-drop operation.
0
Attacker Value
Unknown
CVE-2014-0815
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.
0
Attacker Value
Unknown
CVE-2013-4705
Disclosure Date: September 13, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows remote attackers to inject arbitrary web script or HTML by leveraging UTF-8 encoding.
0
Attacker Value
Unknown
CVE-2013-3211
Disclosure Date: April 19, 2013 (last updated October 05, 2023)
Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe issue."
0
Attacker Value
Unknown
CVE-2013-3210
Disclosure Date: April 19, 2013 (last updated October 05, 2023)
Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.
0