
CVE-2011-3366 – Gentoo Linux Security Advisory 201412-09
https://notcve.org/view.php?id=CVE-2011-3366
29 Nov 2011 — Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text. Rekonq v0.7.0 y anteriores no usan una fuente concreta cuando se renderizan los campos de certificado en un diálogo de seguridad, lo que permite a atacantes remotodos falsificar el nombre común (CN) de un certificado a través de un texto enriquecido. This GLSA contains notification of vulnerabilities found in ... • http://www.kde.org/info/security/advisory-20111003-1.txt • CWE-20: Improper Input Validation •

CVE-2010-2536
https://notcve.org/view.php?id=CVE-2010-2536
02 Aug 2010 — Multiple cross-site scripting (XSS) vulnerabilities in rekonq 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a URL associated with a nonexistent domain name, related to webpage.cpp, aka a "universal XSS" issue; (2) unspecified vectors related to webview.cpp; and the about: views for (3) favorites, (4) bookmarks, (5) closed tabs, and (6) history. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en rekonq 0.5 y anteriores, permite a atacantes... • http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049406.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •