Opera Browser vulnerabilities
274 known vulnerabilities affecting opera/opera_browser.
Total CVEs
274
CISA KEV
0
Public exploits
26
Exploited in wild
1
Severity breakdown
CRITICAL43HIGH23MEDIUM196LOW12
Vulnerabilities
Page 2 of 14
CVE-2012-6462MEDIUMCVSS 5.0≤ 12.10v1.00+105 more2013-01-02
CVE-2012-6462 [MEDIUM] CWE-264 CVE-2012-6462: Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specificatio
Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request.
nvd
CVE-2012-6464MEDIUMCVSS 4.3≤ 12.10v1.00+105 more2013-01-02
CVE-2012-6464 [MEDIUM] CWE-79 CVE-2012-6464: Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arb
Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript code that overrides methods of unspecified native objects in documents that have different origins.
nvd
CVE-2012-6463MEDIUMCVSS 4.3≤ 12.10v1.00+105 more2013-01-02
CVE-2012-6463 [MEDIUM] CWE-79 CVE-2012-6463: Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arb
Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an unspecified sequence of loading of documents and loading of data: URLs.
nvd
CVE-2012-6460MEDIUMCVSS 5.0≤ 11.66v1.00+103 more2013-01-02
CVE-2012-6460 [MEDIUM] CVE-2012-6460: Opera before 11.67 and 12.x before 12.02 allows remote attackers to cause truncation of a dialog, an
Opera before 11.67 and 12.x before 12.02 allows remote attackers to cause truncation of a dialog, and possibly trigger downloading and execution of arbitrary programs, via a crafted web site.
nvd
CVE-2012-6471MEDIUMCVSS 5.0≤ 12.11v1.00+106 more2013-01-02
CVE-2012-6471 [MEDIUM] CVE-2012-6471: Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP reques
Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.
nvd
CVE-2012-6461MEDIUMCVSS 5.0≤ 12.10v1.00+105 more2013-01-02
CVE-2012-6461 [MEDIUM] CWE-20 CVE-2012-6461: The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 all
The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers to trigger a false indication of successful revocation-status checking by causing a failure of a single checking service.
nvd
CVE-2012-4010MEDIUMCVSS 5.0≤ 11.60v5.0+77 more2012-08-30
CVE-2012-4010 [MEDIUM] CVE-2012-4010: Opera before 11.60 allows remote attackers to spoof the address bar via unspecified homograph charac
Opera before 11.60 allows remote attackers to spoof the address bar via unspecified homograph characters, a different vulnerability than CVE-2010-2660.
nvd
CVE-2012-4145CRITICALCVSS 10.0≤ 12.00v12.00+26 more2012-08-06
CVE-2012-4145 [CRITICAL] CVE-2012-4145: Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x befor
Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue."
nvd
CVE-2012-4143MEDIUMCVSS 6.8≤ 12.00v12.00+26 more2012-08-06
CVE-2012-4143 [MEDIUM] CVE-2012-4143: Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows u
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog, a different vulnerability than CVE-2012-1924.
nvd
CVE-2012-4146MEDIUMCVSS 4.3≤ 12.00v1.00+101 more2012-08-06
CVE-2012-4146 [MEDIUM] CWE-119 CVE-2012-4146: Opera before 12.01 allows remote attackers to cause a denial of service (application crash) via a cr
Opera before 12.01 allows remote attackers to cause a denial of service (application crash) via a crafted web site, as demonstrated by the Lenovo "Shop now" page.
nvd
CVE-2012-4144MEDIUMCVSS 4.3≤ 12.00v12.00+26 more2012-08-06
CVE-2012-4144 [MEDIUM] CWE-79 CVE-2012-4144: Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted HTML document.
nvd
CVE-2012-4142MEDIUMCVSS 4.3≤ 12.00v12.00+26 more2012-08-06
CVE-2012-4142 [MEDIUM] CWE-79 CVE-2012-4142: Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, ignores
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, ignores some characters in HTML documents in unspecified circumstances, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.
nvd
CVE-2012-3561CRITICALCVSS 10.0≤ 11.62v5.0+79 more2012-06-14
CVE-2012-3561 [CRITICAL] CWE-119 CVE-2012-3561: Opera before 11.64 does not properly allocate memory for URL strings, which allows remote attackers
Opera before 11.64 does not properly allocate memory for URL strings, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted string.
nvd
CVE-2012-3559CRITICALCVSS 10.0≤ 12.00v6.0+57 more2012-06-14
CVE-2012-3559 [CRITICAL] CVE-2012-3559: Unspecified vulnerability in Opera before 12.00 on Mac OS X has unknown impact and attack vectors, r
Unspecified vulnerability in Opera before 12.00 on Mac OS X has unknown impact and attack vectors, related to a "moderate severity issue."
nvd
CVE-2012-3556CRITICALCVSS 9.3≤ 11.62v5.0+79 more2012-06-14
CVE-2012-3556 [CRITICAL] CWE-20 CVE-2012-3556: Opera before 11.65 does not properly restrict the opening of a pop-up window in response to the firs
Opera before 11.65 does not properly restrict the opening of a pop-up window in response to the first click of a double-click action, which makes it easier for user-assisted remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary code via a crafted web site.
nvd
CVE-2012-3555HIGHCVSS 7.6≤ 11.62v5.0+79 more2012-06-14
CVE-2012-3555 [HIGH] CVE-2012-3555: Opera before 11.65 does not ensure that keyboard sequences are associated with a visible window, whi
Opera before 11.65 does not ensure that keyboard sequences are associated with a visible window, which makes it easier for user-assisted remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary code via a crafted web site, related to a "hidden keyboard navigation" issue.
nvd
CVE-2012-3563MEDIUMCVSS 5.0≤ 11.65v5.0+81 more2012-06-14
CVE-2012-3563 [MEDIUM] CVE-2012-3563: Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via
Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via a web page that contains invalid character encodings.
nvd
CVE-2012-3562MEDIUMCVSS 4.3≤ 11.65v5.0+81 more2012-06-14
CVE-2012-3562 [MEDIUM] CVE-2012-3562: Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (applicat
Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload, as demonstrated by a "multiple origin camera test" page.
nvd
CVE-2012-3568MEDIUMCVSS 5.0≤ 11.65v5.0+81 more2012-06-14
CVE-2012-3568 [MEDIUM] CVE-2012-3568: Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via
Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via crafted WebGL content, as demonstrated by a codeflow.org WebGL demo.
nvd
CVE-2012-3560MEDIUMCVSS 4.3≤ 11.64v5.0+80 more2012-06-14
CVE-2012-3560 [MEDIUM] CWE-264 CVE-2012-3560: Opera before 11.65 does not ensure that the address field corresponds to the displayed web page duri
Opera before 11.65 does not ensure that the address field corresponds to the displayed web page during blocked navigation, which makes it easier for remote attackers to conduct spoofing attacks by detecting and preventing attempts to load a different web page.
nvd