Opera Browser vulnerabilities
274 known vulnerabilities affecting opera/opera_browser.
Total CVEs
274
CISA KEV
0
Public exploits
26
Exploited in wild
1
Severity breakdown
CRITICAL43HIGH23MEDIUM196LOW12
Vulnerabilities
Page 10 of 14
CVE-2008-4725MEDIUMCVSS 4.3PoCv9.522008-10-23
CVE-2008-4725 [MEDIUM] CVE-2008-4725: Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to injec
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a different vector than CVE-2008-4696. NOTE: some of these issues were addressed before 9.60.
nvd
CVE-2008-4697MEDIUMCVSS 4.3≤ 9.60v5.0+55 more2008-10-23
CVE-2008-4697 [MEDIUM] CWE-79 CVE-2008-4697: The Fast Forward feature in Opera before 9.61, when a page is located in a frame, executes a javascr
The Fast Forward feature in Opera before 9.61, when a page is located in a frame, executes a javascript: URL in the context of the outermost page instead of the page that contains this URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2008-4292CRITICALCVSS 10.0≤ 9.51v5.0+52 more2008-09-27
CVE-2008-4292 [CRITICAL] CWE-255 CVE-2008-4292: Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL,
Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL, which has unknown impact and attack vectors. NOTE: it is not clear whether this is a vulnerability, but the vendor included it in a security section of the advisory.
nvd
CVE-2008-4197HIGHCVSS 8.8fixed in 9.522008-09-27
CVE-2008-4197 [HIGH] CWE-908 CVE-2008-4197: Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.
nvd
CVE-2008-4198MEDIUMCVSS 5.0≤ 9.51v5.0+52 more2008-09-27
CVE-2008-4198 [MEDIUM] CVE-2008-4198: Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays
Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays a padlock icon and offers a security information dialog reporting a secure connection, which might allow remote attackers to trick a user into performing unsafe actions on the http page.
nvd
CVE-2008-4196MEDIUMCVSS 4.3≤ 9.51v5.0+52 more2008-09-27
CVE-2008-4196 [MEDIUM] CWE-79 CVE-2008-4196: Cross-site scripting (XSS) vulnerability in Opera before 9.52 allows remote attackers to inject arbi
Cross-site scripting (XSS) vulnerability in Opera before 9.52 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2008-4199MEDIUMCVSS 5.0≤ 9.51v5.0+52 more2008-09-27
CVE-2008-4199 [MEDIUM] CWE-200 CVE-2008-4199: Opera before 9.52 does not prevent use of links from web pages to feed source files on the local dis
Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filenames via vectors involving "detection of JavaScript events and appropriate manipulation."
nvd
CVE-2008-4195MEDIUMCVSS 5.0≤ 9.51v5.0+52 more2008-09-27
CVE-2008-4195 [MEDIUM] CWE-264 CVE-2008-4195: Opera before 9.52 does not properly restrict the ability of a framed web page to change the address
Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows remote attackers to trigger the display of an arbitrary address in a frame via unspecified use of web script.
nvd
CVE-2008-4200MEDIUMCVSS 6.4≤ 9.51v5.0+52 more2008-09-27
CVE-2008-4200 [MEDIUM] CWE-20 CVE-2008-4200: Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual
Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows remote attackers to change this field to display the URL of a page containing web script controlled by the attacker.
nvd
CVE-2008-3078HIGHCVSS 7.8≤ 9.50v1.00+67 more2008-07-09
CVE-2008-3078 [HIGH] CWE-200 CVE-2008-3078: Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, wh
Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized memory contents by using JavaScript to read a canvas image.
nvd
CVE-2008-2715MEDIUMCVSS 5.0≤ 9.50v1.00+67 more2008-06-16
CVE-2008-2715 [MEDIUM] CWE-200 CVE-2008-2715: Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images vi
Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images via HTML CANVAS elements that use the images as patterns.
nvd
CVE-2008-2714MEDIUMCVSS 5.0≤ 9.25v1.00+63 more2008-06-16
CVE-2008-2714 [MEDIUM] CVE-2008-2714: Opera before 9.26 allows remote attackers to misrepresent web page addresses using "certain characte
Opera before 9.26 allows remote attackers to misrepresent web page addresses using "certain characters" that "cause the page address text to be misplaced."
nvd
CVE-2008-2716MEDIUMCVSS 5.0fixed in 9.52008-06-16
CVE-2008-2716 [MEDIUM] CWE-1021 CVE-2008-2716: Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trust
Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trusted frames on the same parent page by modifying the location, which can facilitate phishing attacks.
nvd
CVE-2008-1762CRITICALCVSS 9.3PoC≤ 9.26v5.0+49 more2008-04-12
CVE-2008-1762 [CRITICAL] CWE-399 CVE-2008-1762: Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute
Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern in an HTML CANVAS element, which triggers memory corruption.
nvd
CVE-2008-1080MEDIUMCVSS 6.8≤ 9.25v1.00+63 more2008-02-29
CVE-2008-1080 [MEDIUM] CWE-20 CVE-2008-1080: Opera before 9.26 allows user-assisted remote attackers to read arbitrary files by tricking a user i
Opera before 9.26 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename into a file input.
nvd
CVE-2008-1081MEDIUMCVSS 6.8≤ 9.25v1.00+63 more2008-02-29
CVE-2008-1081 [MEDIUM] CWE-94 CVE-2008-1081: Opera before 9.26 allows user-assisted remote attackers to execute arbitrary script via images that
Opera before 9.26 allows user-assisted remote attackers to execute arbitrary script via images that contain custom comments, which are treated as script when the user displays the image properties.
nvd
CVE-2008-1082MEDIUMCVSS 4.3≤ 9.25v1.00+63 more2008-02-29
CVE-2008-1082 [MEDIUM] CWE-79 CVE-2008-1082: Opera before 9.26 allows remote attackers to "bypass sanitization filters" and conduct cross-site sc
Opera before 9.26 allows remote attackers to "bypass sanitization filters" and conduct cross-site scripting (XSS) attacks via crafted attribute values in an XML document, which are not properly handled during DOM presentation.
nvd
CVE-2007-6521CRITICALCVSS 10.0≤ 9.24v1.00+62 more2007-12-24
CVE-2007-6521 [CRITICAL] CWE-310 CVE-2007-6521: Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via
Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.
nvd
CVE-2007-6523HIGHCVSS 7.8v9.0v9.01+9 more2007-12-24
CVE-2007-6523 [HIGH] CWE-189 CVE-2007-6523: Algorithmic complexity vulnerability in Opera 9.50 beta and 9.x before 9.25 allows remote attackers
Algorithmic complexity vulnerability in Opera 9.50 beta and 9.x before 9.25 allows remote attackers to cause a denial of service (CPU consumption) via a crafted bitmap (BMP) file that triggers a large number of calculations and checks.
nvd
CVE-2007-6524HIGHCVSS 7.8≤ 9.24v5.0+47 more2007-12-24
CVE-2007-6524 [HIGH] CWE-200 CVE-2007-6524: Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a craf
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta, a related issue to CVE-2008-0420.
nvd