CVE-2010-2666Browser vulnerability

CWE-2643 documents3 sources
Severity
9.3CRITICALNVD
EPSS
3.2%
top 13.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 8
Latest updateMay 14

Description

Opera before 10.54 on Windows and Mac OS X does not properly enforce permission requirements for widget filesystem access and directory selection, which allows user-assisted remote attackers to create or modify arbitrary files, and consequently execute arbitrary code, via widget File I/O operations.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDopera/opera_browser10.53+63

🔴Vulnerability Details

2
GHSA
GHSA-wqf6-gm3j-5p78: Opera before 102022-05-14
CVEList
CVE-2010-2666: Opera before 102010-07-07
CVE-2010-2666 — Opera Browser vulnerability | cvebase