Skip to main content

Vendor/product archive

opera / opera CVEs

Beta · best-effort

19 CVEs tagged to opera / opera8 Critical, 0 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2020-6159

Published Dec 23, 2020

URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this rem…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12278

Published Mar 12, 2020

Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several Unicode characters.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19788

Published Dec 18, 2019

Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to byp…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5227

Published Sep 7, 2012

Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrate…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2068

Published Jun 15, 2009

Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an htt…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5679

Published Dec 19, 2008

The HTML parsing engine in Opera before 9.63 allows remote attackers to execute arbitrary code via crafted web pages that trigger an invalid pointer calculation and heap corruptio…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5428

Published Dec 11, 2008

Opera 9.51 on Windows XP does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5178

Published Nov 20, 2008

Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4795

Published Oct 30, 2008

The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4794

Published Oct 30, 2008

Opera before 9.62 allows remote attackers to execute arbitrary commands via the History Search results page, a different vulnerability than CVE-2008-4696.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4696

Published Oct 23, 2008

Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4695

Published Oct 23, 2008

Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cached Java applet and then launc…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4293

Published Sep 27, 2008

Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attackers to cause a denial of service (crash) and possibly execute…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3172

Published Jul 14, 2008

Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attackers to perform a session fixati…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3079

Published Jul 9, 2008

Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1761

Published Apr 12, 2008

Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted newsfeed source, which triggers an invalid memory…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1764

Published Apr 12, 2008

Unspecified vulnerability in Opera before 9.27 has unknown impact and attack vectors related to "keyboard handling of password inputs."

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1561

Published Dec 31, 2003

Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1