Advisory
- Advisory: XSLT can be used to retrieve random contents of unrelated documents
- Advisory: HTTP Content-Length header can be used to execute arbitrary code
- Advisory: Cross-domain data theft with CSS load
- Advisory: Heap buffer overflow in string to number conversion
- Advisory: Error messages can leak onto unrelated sites
- Advisory: Web fonts can be used to spoof the page address
- Advisory: Opera may allow scripts to access feeds
- Advisory: Certain domain names can allow execution of arbitrary code
- Advisory: *.com accepted as wildcard match in SSL/TLS name matching
- Advisory: MD2 algorithm used by security certificates is considered weak