Skip to main content

Vendor archive

opera CVEs

Beta · best-effort

311 CVEs tagged to vendor opera54 Critical, 25 High, 218 Medium, 14 Low, 0 Unrated.

CVE-2018-16135

Published Dec 26, 2022

The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23253

Published Jan 11, 2021

Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6159

Published Dec 23, 2020

URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this rem…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6157

Published Nov 13, 2020

Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12278

Published Mar 12, 2020

Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several Unicode characters.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19788

Published Dec 18, 2019

Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to byp…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18624

Published Oct 29, 2019

Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by mi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-13607

Published Jul 18, 2019

The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigation to a javascript: URL.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18913

Published Mar 21, 2019

Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6608

Published Mar 28, 2018

In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6908

Published Jan 26, 2017

Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode char…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5101

Published Jun 29, 2016

Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted e-mail message.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1870

Published Feb 6, 2014

Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-drop operation.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0815

Published Feb 6, 2014

The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4705

Published Sep 13, 2013

Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows remote attackers to inject arbitrary web script or HTML by leveraging UTF-8 encoding.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3211

Published Apr 19, 2013

Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe issue."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3210

Published Apr 19, 2013

Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a differ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1618

Published Feb 8, 2013

The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1639

Published Feb 8, 2013

Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that tri…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1638

Published Feb 8, 2013

Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 311 CVEsPage 1 of 13