VYPR

Opera

by Opera

CVEs (291)

  • CVE-2008-4197HigSep 27, 2008
    risk 0.58cvss 8.8epss 0.06

    Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via…

  • CVE-2018-18913HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.00

    Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system…

  • CVE-2009-3046HigSep 2, 2009
    risk 0.49cvss 7.5epss 0.01

    Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certificate.

  • CVE-2020-6159MedDec 23, 2020
    risk 0.40cvss 6.1epss 0.01

    URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this removal was not performed. This could allow users to be socially engineered to run an XSS attack…

  • CVE-2019-19788MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without…

  • CVE-2016-7152MedSep 6, 2016
    risk 0.36cvss 5.3epss 0.14

    The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a…

  • CVE-2019-12278MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.01

    Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several Unicode characters. The rendering mechanism, in conjunction with the "first strong character" concept, may improperly…

  • CVE-2018-6608MedMar 28, 2018
    risk 0.28cvss 4.3epss 0.03

    In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.

  • CVE-2008-4696Oct 23, 2008
    risk 0.07cvss epss 0.46

    Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka…

  • CVE-2008-5178Nov 20, 2008
    risk 0.06cvss epss 0.32

    Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680.

  • CVE-2010-1349Apr 12, 2010
    risk 0.05cvss epss 0.20

    Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow.

  • CVE-2013-1638Feb 8, 2013
    risk 0.04cvss epss 0.08

    Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.

  • CVE-2012-6470Jan 2, 2013
    risk 0.04cvss epss 0.08

    Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a malformed image.

  • CVE-2011-2628Jul 1, 2011
    risk 0.04cvss epss 0.13

    Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload.

  • CVE-2008-7245Sep 18, 2009
    risk 0.04cvss epss 0.06

    Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

  • CVE-2009-1234Apr 2, 2009
    risk 0.04cvss epss 0.07

    Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected.

  • CVE-2008-5680Dec 19, 2008
    risk 0.04cvss epss 0.08

    Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-assisted remote attackers to execute arbitrary code via a long host name in a file: URL. NOTE: this might overlap CVE-2008-5178.

  • CVE-2008-4694Oct 23, 2008
    risk 0.04cvss epss 0.10

    Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a redirect that specifies a crafted URL.

  • CVE-2008-1762Apr 12, 2008
    risk 0.04cvss epss 0.08

    Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern in an HTML CANVAS element, which triggers memory corruption.

  • CVE-2007-2274Apr 25, 2007
    risk 0.04cvss epss 0.08

    The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the original disclosure refers to this as a memory leak, but it is not certain.

Page 1 of 15