Skip to main content

Vendor/product archive

opera / opera_browser CVEs

Beta · best-effort

285 CVEs tagged to opera / opera_browser45 Critical, 24 High, 202 Medium, 14 Low, 0 Unrated.

CVE-2018-18913

Published Mar 21, 2019

Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6608

Published Mar 28, 2018

In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6908

Published Jan 26, 2017

Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode char…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1870

Published Feb 6, 2014

Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-drop operation.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0815

Published Feb 6, 2014

The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4705

Published Sep 13, 2013

Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows remote attackers to inject arbitrary web script or HTML by leveraging UTF-8 encoding.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3211

Published Apr 19, 2013

Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe issue."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3210

Published Apr 19, 2013

Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a differ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1618

Published Feb 8, 2013

The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1639

Published Feb 8, 2013

Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that tri…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1638

Published Feb 8, 2013

Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-1637

Published Feb 8, 2013

Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6472

Published Jan 2, 2013

Opera before 12.12 on UNIX uses weak permissions for the profile directory, which allows local users to obtain sensitive information by reading a (1) cache file, (2) password file…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6471

Published Jan 2, 2013

Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6470

Published Jan 2, 2013

Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6469

Published Jan 2, 2013

Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6468

Published Jan 2, 2013

Heap-based buffer overflow in Opera before 12.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long HTTP response.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6467

Published Jan 2, 2013

Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for remote attackers to conduct phishing…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6466

Published Jan 2, 2013

Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from process memory by u…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6465

Published Jan 2, 2013

Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 285 CVEsPage 1 of 12