Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

717 CVEs tagged with CWE-34667 Critical, 232 High, 387 Medium, 30 Low, 1 Unrated.

CVE-2012-4193

Published Oct 12, 2012

Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in…

CVSS 6.8 · Medium

CVE-2011-3072

Published Apr 5, 2012

Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3956

Published Feb 9, 2012

The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2856

Published Sep 19, 2011

Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0877

Published May 2, 2005

Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0981

Published Jan 5, 2004

FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilita…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0174

Published May 12, 2003

The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to l…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1549

Published Nov 16, 1999

Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 701-717 of 717 CVEsPage 29 of 29