VYPR

Opera For Android

by Opera

CVEs (5)

  • CVE-2020-6159MedDec 23, 2020
    risk 0.40cvss 6.1epss 0.01

    URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this removal was not performed. This could allow users to be socially engineered to run an XSS attack…

  • CVE-2016-6908MedJan 26, 2017
    risk 0.40cvss 6.1epss 0.01

    Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are rendered combined with (first strong…

  • CVE-2019-19788MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without…

  • CVE-2020-6158MedFeb 21, 2025
    risk 0.31cvss 4.7epss 0.00

    Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to impersonate another page and trick a user…

  • CVE-2019-12278MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.01

    Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several Unicode characters. The rendering mechanism, in conjunction with the "first strong character" concept, may improperly…