Vulnerability index

Browse CVEs

208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opera Browser HIGH 10.0
CVE-2010-4586

The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, possibly a …

Fix: after 11.00
Fix from $1,950 2010-12-22
Opera Browser HIGH 9.3
CVE-2010-4587

Opera before 11.00 on Windows does not properly implement the Insecure Third Party Module warning message, which might make it easier for user-assist…

Fix: after 11.00
Fix from $1,950 2010-12-22
Opera Browser MEDIUM 5.0
CVE-2010-4579

Opera before 11.00 does not properly constrain dialogs to appear on top of rendered documents, which makes it easier for remote attackers to trick us…

Fix: after 11.00
Fix from $1,600 2010-12-22
Opera Browser MEDIUM 5.0
CVE-2010-4580

Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive in…

Fix: after 11.00
Fix from $1,600 2010-12-22
Opera Browser MEDIUM 5.0
CVE-2010-4582

Opera before 11.00 does not properly handle security policies during updates to extensions, which might allow remote attackers to bypass intended acc…

Fix: after 11.00
Fix from $1,600 2010-12-22
Opera Browser MEDIUM 5.0
CVE-2010-4585

Unspecified vulnerability in the auto-update functionality in Opera before 11.00 allows remote attackers to cause a denial of service (application cr…

Fix: after 11.00
Fix from $1,600 2010-12-22
Opera Browser HIGH 9.3
CVE-2010-4045

Opera before 10.63 does not properly restrict web script in unspecified circumstances involving reloads and redirects, which allows remote attackers …

Fix: after 10.62
Fix from $1,950 2010-10-21
Opera Browser MEDIUM 5.0
CVE-2010-3020

The news-feed preview feature in Opera before 10.61 does not properly remove scripts, which allows remote attackers to force subscriptions to arbitra…

Fix: after 10.60
Fix from $1,600 2010-08-16
Opera Browser HIGH 9.3
CVE-2010-3019EPSS 5%

Heap-based buffer overflow in Opera before 10.61 allows remote attackers to execute arbitrary code or cause a denial of service (application crash or…

Fix: after 10.60
Fix from $1,950 2010-08-16
Opera Browser MEDIUM 6.8
CVE-2010-2576

Opera before 10.61 does not properly suppress clicks on download dialogs that became visible after a recent tab change, which allows remote attackers…

Fix: after 10.60
Fix from $1,600 2010-08-16
Opera Browser HIGH 9.3
CVE-2010-2657

Opera before 10.60 on Windows and Mac OS X does not properly prevent certain double-click operations from running a program located on a web site, wh…

Fix: 10.60+
Fix from $1,950 2010-07-08
Opera Browser HIGH 9.3
CVE-2010-2666EPSS 5%

Opera before 10.54 on Windows and Mac OS X does not properly enforce permission requirements for widget filesystem access and directory selection, wh…

Fix: after 10.53
Fix from $1,950 2010-07-08
Opera Browser HIGH 10.0
CVE-2010-2421

Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "highly seve…

Fix: after 10.53
Fix from $1,950 2010-06-22
Opera Browser MEDIUM 5.0
CVE-2010-1989

Opera 9.52 executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remot…

No fix yet
Fix from $1,600 2010-05-20
Opera Browser MEDIUM 5.0
CVE-2010-1993

Opera 9.52 does not properly handle an IFRAME element with a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of ser…

No fix yet
Fix from $1,600 2010-05-20
Opera Browser HIGH 9.3
CVE-2010-1728EPSS 7%

Opera before 10.53 on Windows and Mac OS X does not properly handle a series of document modifications that occur asynchronously, which allows remote…

Fix: after 10.52
Fix from $1,950 2010-05-06
Opera Browser HIGH 10.0
CVE-2010-1349EPSS 20%

Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a he…

Patch available
Fix from $1,950 2010-04-12
Opera Browser MEDIUM 5.0
CVE-2010-1310

Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other…

Mitigation only
Fix from $1,600 2010-04-08
Opera Browser HIGH 10.0
CVE-2009-4072

Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."

Fix: after 10.10
Fix from $1,950 2009-11-24
Opera Browser MEDIUM 5.8
CVE-2009-4071

Opera before 10.10, when exception stacktraces are enabled, places scripting error messages from a web site into variables that can be read by a diff…

Fix: after 10.10
Fix from $1,600 2009-11-24
Opera Browser HIGH 9.3
CVE-2009-3831EPSS 6%

Opera before 10.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cra…

Fix: 10.01+
Fix from $1,950 2009-10-30
Opera Browser MEDIUM 5.8
CVE-2009-3832

Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof…

Fix: 10.01+
Fix from $1,600 2009-10-30
Opera Browser MEDIUM 5.0
CVE-2008-7245EPSS 6%

Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a …

Fix: after 9.52
Fix from $1,600 2009-09-18
Opera Browser MEDIUM 5.0
CVE-2009-3269

Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a series of automatic submissions of a form contain…

Fix: after 9.52
Fix from $1,600 2009-09-18
Opera Browser HIGH 7.5
CVE-2009-3046

Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validati…

Fix: 10.00+
Fix from $1,950 2009-09-02
Opera Browser MEDIUM 5.0
CVE-2009-3045

Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbit…

Fix: after 10.00
Fix from $1,600 2009-09-02
Opera Browser MEDIUM 5.0
CVE-2009-3049

Opera before 10.00 does not properly display all characters in Internationalized Domain Names (IDN) in the address bar, which allows remote attackers…

Fix: after 10.00
Fix from $1,600 2009-09-02
Opera Browser MEDIUM 5.0
CVE-2009-3044

Opera before 10.00 does not properly handle a (1) '\0' character or (2) invalid wildcard character in a domain name in the subject's Common Name (CN)…

Fix: after 10.00
Fix from $1,600 2009-09-02
Opera Browser MEDIUM 5.0
CVE-2009-2577

Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption, and application hang) via a long Unicode str…

Fix: after 9.52
Fix from $1,600 2009-07-22
Opera Browser MEDIUM 6.8
CVE-2009-2059

Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from …

Fix: after 9.22
Fix from $1,600 2009-06-15