VYPR

Opera

by Opera

CVEs (291)

  • CVE-2007-0126Jan 9, 2007
    risk 0.04cvss —epss 0.11

    Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker.

  • CVE-2006-3353Jul 6, 2006
    risk 0.04cvss —epss 0.08

    Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-bounds memory access, related to an iframe and JavaScript that accesses certain style sheets properties.

  • CVE-2006-3199Jun 23, 2006
    risk 0.04cvss —epss 0.15

    Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which triggers an out-of-bounds operation.

  • CVE-2006-1834Apr 19, 2006
    risk 0.04cvss —epss 0.12

    Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check. NOTE: a sign extension problem makes the attack easier with shorter strings.

  • CVE-2005-4718Dec 31, 2005
    risk 0.04cvss —epss 0.10

    Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file with a "content: url(0);" style attribute, a "bodyA" tag, a long string, and a "u" tag with a long attribute, as demonstrated by opera.html; and (2) a BGSOUND…

  • CVE-2004-1491Dec 31, 2004
    risk 0.04cvss —epss 0.13

    Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

  • CVE-2004-2491Dec 31, 2004
    risk 0.04cvss —epss 0.06

    A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing…

  • CVE-2003-1387Dec 31, 2003
    risk 0.04cvss —epss 0.15

    Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.

  • CVE-2003-1396Dec 31, 2003
    risk 0.04cvss —epss 0.09

    Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.

  • CVE-2003-0870Nov 17, 2003
    risk 0.04cvss —epss 0.15

    Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.

  • CVE-2001-1491Dec 31, 2001
    risk 0.04cvss —epss 0.07

    Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

  • CVE-2010-5227Sep 7, 2012
    risk 0.03cvss —epss 0.01

    Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .htm, .mht, .mhtml, .xht, .xhtm, or .xhtl file. NOTE: some of…

  • CVE-2011-4684Dec 7, 2011
    risk 0.03cvss —epss 0.06

    Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."

  • CVE-2011-2641Jul 1, 2011
    risk 0.03cvss —epss 0.05

    Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a FONT element within an IFRAME element after changing the SRC attribute of this IFRAME element to an about:blank value.

  • CVE-2008-4795Oct 30, 2008
    risk 0.03cvss —epss 0.04

    The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.

  • CVE-2008-4725Oct 23, 2008
    risk 0.03cvss —epss 0.05

    Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a different vector than…

  • CVE-2007-1563Mar 21, 2007
    risk 0.03cvss —epss 0.05

    The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

  • CVE-2003-1397Dec 31, 2003
    risk 0.03cvss —epss 0.06

    The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.

  • CVE-2002-2312Dec 31, 2002
    risk 0.03cvss —epss 0.02

    Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.

  • CVE-2002-2358Dec 31, 2002
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL.

Page 2 of 15