Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2015-02-01 CVE-2014-7287 Injection vulnerability in Symantec Encryption Management Server and PGP Universal Server
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.
network
low complexity
symantec CWE-74
5.0
2014-11-28 CVE-2014-8423 Injection vulnerability in Arris Vap2500 Firmware 08.41
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.
network
low complexity
arris CWE-74
critical
10.0
2012-10-29 CVE-2012-4196 Injection vulnerability in multiple products
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
network
low complexity
mozilla opensuse suse canonical redhat CWE-74
6.4
2009-05-22 CVE-2009-1781 Injection vulnerability in Frax PHP Recommend 1.3
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.
network
roboform frax CWE-74
7.5
2007-08-08 CVE-2007-4190 Injection vulnerability in Joomla Joomla!
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter.
network
joomla CWE-74
4.3
2005-11-22 CVE-2005-3750 Injection vulnerability in Opera Browser
Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that another product provides in a command line argument when launching Opera.
network
low complexity
opera CWE-74
7.5
2005-09-21 CVE-2005-3007 Injection vulnerability in Opera Browser
Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content.
network
high complexity
opera CWE-74
2.6
2005-01-10 CVE-2004-1157 Injection vulnerability in Opera Browser
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
low complexity
opera CWE-74
7.5
2004-12-31 CVE-2004-2570 Injection vulnerability in Opera Browser
Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.
network
low complexity
opera CWE-74
5.0