Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2012-10-29 CVE-2012-4196 Injection vulnerability in multiple products
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
network
low complexity
mozilla opensuse suse canonical redhat CWE-74
6.4
2009-05-22 CVE-2009-1781 Injection vulnerability in Frax PHP Recommend 1.3
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.
network
roboform frax CWE-74
7.5
2007-08-08 CVE-2007-4190 Injection vulnerability in Joomla Joomla!
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter.
network
joomla CWE-74
4.3
2005-11-22 CVE-2005-3750 Injection vulnerability in Opera Browser
Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that another product provides in a command line argument when launching Opera.
network
low complexity
opera CWE-74
7.5
2005-09-21 CVE-2005-3007 Injection vulnerability in Opera Browser
Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content.
network
high complexity
opera CWE-74
2.6
2005-01-10 CVE-2004-1157 Injection vulnerability in Opera Browser
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
low complexity
opera CWE-74
7.5
2004-12-31 CVE-2004-2570 Injection vulnerability in Opera Browser
Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.
network
low complexity
opera CWE-74
5.0