Lines 34-39
Link Here
|
34 |
|
34 |
|
35 |
--> |
35 |
--> |
36 |
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> |
36 |
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> |
|
|
37 |
<vuln vid="f5c4d7f7-9f4b-11dd-bab1-001999392805"> |
38 |
<topic>opera -- multiple vulnerabilities</topic> |
39 |
<affects> |
40 |
<package> |
41 |
<name>opera</name> |
42 |
<range><lt>9.61.20081017</lt></range> |
43 |
</package> |
44 |
</affects> |
45 |
<description> |
46 |
<body xmlns="http://www.w3.org/1999/xhtml"> |
47 |
<p>Opera reports:</p> |
48 |
<blockquote cite="http://www.opera.com/support/search/view/903/"> |
49 |
<p>Certain constructs are not escaped correctly by Opera's |
50 |
History Search results. These can be used to inject scripts |
51 |
into the page, which can then be used to look through the user's |
52 |
browsing history, including the contents of the pages they have |
53 |
visited. These may contain sensitive information.</p> |
54 |
</blockquote> |
55 |
<blockquote cite="http://www.opera.com/support/search/view/904/"> |
56 |
<p>If a link that uses a JavaScript URL triggers Opera's Fast |
57 |
Forward feature, when the user activates Fast Forward, the |
58 |
script should run on the current page. When a page is held in a |
59 |
frame, the script is incorrectly executed on the outermost page, |
60 |
not the page where the URL was located. This can be used to |
61 |
execute scripts in the context of an unrelated frame, which |
62 |
allows cross-site scripting.</p> |
63 |
</blockquote> |
64 |
<blockquote cite="http://www.opera.com/support/search/view/905/"> |
65 |
<p>When Opera is previewing a news feed, some scripts are not |
66 |
correctly blocked. These scripts are able to subscribe the user |
67 |
to any feed URL that the attacker chooses, and can also view |
68 |
the contents of any feeds that the user is subscribed to. |
69 |
These may contain sensitive information.</p> |
70 |
</blockquote> |
71 |
</body> |
72 |
</description> |
73 |
<references> |
74 |
<url>http://www.opera.com/support/search/view/903/</url> |
75 |
<url>http://www.opera.com/support/search/view/904/</url> |
76 |
<url>http://www.opera.com/support/search/view/905/</url> |
77 |
</references> |
78 |
<dates> |
79 |
<discovery>2008-10-17</discovery> |
80 |
<entry>2008-10-21</entry> |
81 |
</dates> |
82 |
</vuln> |
83 |
|
37 |
<vuln vid="06eac338-9ddf-11dd-813f-000e35248ad7"> |
84 |
<vuln vid="06eac338-9ddf-11dd-813f-000e35248ad7"> |
38 |
<topic>libxine -- denial of service vulnerability</topic> |
85 |
<topic>libxine -- denial of service vulnerability</topic> |
39 |
<affects> |
86 |
<affects> |