VYPR
Vendor

Opera

Opera is a multinational technology corporation headquartered in Oslo, Norway, with additional offices in Europe, China, and Africa. Opera offers a range of products and services that include PC and mobile web browsers, GameMaker and gaming portals, the Opera News content recommendation products, the Opera Ads platform, and a number of Web3 and e-commerce products and services. The company's total user base is 296 million monthly active users.

Founded 1995
Products
13
CVEs
323
Across products
605
Status
Private

Products

13

Recent CVEs

323
View all 323 CVEs →
  • CVE-2019-18624CriOct 29, 2019
    risk 0.64cvss 9.8epss 0.01

    Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553,…

  • CVE-2008-4197HigSep 27, 2008
    risk 0.58cvss 8.8epss 0.06

    Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via…

  • CVE-2016-5101HigJun 29, 2016
    risk 0.57cvss 8.8epss 0.03

    Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted e-mail message.

  • CVE-2018-18913HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.00

    Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system…

  • CVE-2009-3046HigSep 2, 2009
    risk 0.49cvss 7.5epss 0.01

    Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certificate.

  • CVE-2018-16135MedDec 26, 2022
    risk 0.42cvss 6.5epss 0.01

    The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

  • CVE-2020-6159MedDec 23, 2020
    risk 0.40cvss 6.1epss 0.01

    URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this removal was not performed. This could allow users to be socially engineered to run an XSS attack…

  • CVE-2019-13607MedJul 18, 2019
    risk 0.40cvss 6.1epss 0.01

    The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigation to a javascript: URL.

  • CVE-2016-4075MedApr 21, 2017
    risk 0.40cvss 6.1epss 0.01

    Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.

  • CVE-2016-6908MedJan 26, 2017
    risk 0.40cvss 6.1epss 0.01

    Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are rendered combined with (first strong…

  • CVE-2019-19788MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without…

  • CVE-2016-7153MedSep 6, 2016
    risk 0.36cvss 5.3epss 0.14

    The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a…

  • CVE-2016-7152MedSep 6, 2016
    risk 0.36cvss 5.3epss 0.14

    The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a…

  • CVE-2021-23253MedJan 11, 2021
    risk 0.35cvss 5.3epss 0.01

    Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.attacker.com. With the URL being left-aligned, the user will only see the front part (e.g.…

  • CVE-2015-4000LowMay 21, 2015
    risk 0.35cvss 3.7epss 1.00

    The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by…

  • CVE-2020-6158MedFeb 21, 2025
    risk 0.31cvss 4.7epss 0.00

    Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to impersonate another page and trick a user…

  • CVE-2020-6157MedNov 13, 2020
    risk 0.28cvss 4.3epss 0.01

    Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to impersonate another page and trick a user…

  • CVE-2019-12278MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.01

    Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several Unicode characters. The rendering mechanism, in conjunction with the "first strong character" concept, may improperly…

  • CVE-2018-6608MedMar 28, 2018
    risk 0.28cvss 4.3epss 0.03

    In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.

  • CVE-2008-4696Oct 23, 2008
    risk 0.07cvss epss 0.46

    Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka…