CVE-2011-1824Improper Input Validation in Browser

Severity
4.3MEDIUMNVD
EPSS
7.9%
top 7.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 10
Latest updateMay 14

Description

The VEGAOpBitmap::AddLine function in Opera before 10.61 does not properly initialize memory during processing of the SIZE attribute of a SELECT element, which allows remote attackers to trigger an invalid memory write operation, and consequently cause a denial of service (application crash) or possibly execute arbitrary code, via a large integer attribute value.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDopera/opera_browser10.60+69

🔴Vulnerability Details

2
GHSA
GHSA-j7qf-vq2m-64m9: The VEGAOpBitmap::AddLine function in Opera before 102022-05-14
CVEList
CVE-2011-1824: The VEGAOpBitmap::AddLine function in Opera before 102011-05-10
CVE-2011-1824 — Improper Input Validation in Browser | cvebase