CAN-2005-2260
The browser user interface does not properly distinguish between
user-generated events and untrusted synthetic events, which makes
it easier for remote attackers to perform dangerous actions that
normally could only be performed manually by the user.
CAN-2005-2261
XML scripts ran even when Javascript disabled.
CAN-2005-2262
The user can be tricked to executing arbitrary JavaScript code by
using a JavaScript URL as wallpaper.
CAN-2005-2263
It is possible for a remote attacker to execute a callback
function in the context of another domain (i.e. frame).
CAN-2005-2264
By opening a malicious link in the sidebar it is possible for
remote attackers to steal sensitive information.
CAN-2005-2265
Missing input sanitising of InstallVersion.compareTo() can cause
the application to crash.
CAN-2005-2266
Remote attackers could steal sensitive information such as cookies
...
Get the latest Linux and open source security news straight to your inbox.