CVE-2010-3262
https://notcve.org/view.php?id=CVE-2010-3262
Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before 3.0.0.4114 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed. Vulnerabilidad de ejecución de comandos en sitios cruzados en Flock Browser v3.x antes de v3.0.0.4114 permite a atacantes remotos ejecutar HTML o secuencias de comandos web de su elección a través de un feed RSS modificado para tal fin. • http://flock.com/security http://www.securityfocus.com/archive/1/513701/100/0/threaded http://www.securityfocus.com/bid/43225 https://exchange.xforce.ibmcloud.com/vulnerabilities/61820 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2006-6954
https://notcve.org/view.php?id=CVE-2006-6954
Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723. Flock beta 1 0.7 permite a atacantes remotos provocar una denegación de servicio (cierre de aplicación) mediante una página web que contiene un gran número de etiquetas de marquesina (marquee) anidadas, un problema relacionado con CVE-2006-2723. • http://www.securityfocus.com/archive/1/438144/100/100/threaded http://www.securityfocus.com/archive/1/438365/100/100/threaded http://www.securityfocus.com/archive/1/439064/100/100/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/26898 • CWE-20: Improper Input Validation •