Vulnerability index

Browse CVEs

208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opera Browser MEDIUM 6.8
CVE-2009-2063

Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to exe…

Fix: after 9.24
Fix from $1,600 2009-06-15
Opera Browser MEDIUM 6.8
CVE-2009-2067

Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary…

Fix: after 9.22
Fix from $1,600 2009-06-15
Opera Browser MEDIUM 6.8
CVE-2009-2070

Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attacke…

Mitigation only
Fix from $1,600 2009-06-15
Opera MEDIUM 5.8
CVE-2009-2068

Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute a…

Mitigation only
Fix from $1,600 2009-06-15
Opera Browser HIGH 9.3
CVE-2009-1599

Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, …

Mitigation only
Fix from $1,950 2009-05-11
Opera Browser HIGH 10.0
CVE-2009-0916

Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."

Fix: after 9.63
Fix from $1,950 2009-03-16
Opera Browser HIGH 9.3
CVE-2009-0914

Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption.

Fix: after 9.63
Fix from $1,950 2009-03-16
Opera Browser MEDIUM 6.8
CVE-2009-0915

Opera before 9.64 allows remote attackers to conduct cross-domain scripting attacks via unspecified vectors related to plug-ins.

Fix: 9.64+
Fix from $1,600 2009-03-16
Opera HIGH 9.3
CVE-2008-5679

The HTML parsing engine in Opera before 9.63 allows remote attackers to execute arbitrary code via crafted web pages that trigger an invalid pointer …

Fix: after 9.62
Fix from $1,950 2008-12-19
Opera Browser HIGH 9.3
CVE-2008-5680EPSS 8%

Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-…

Fix: after 9.62
Fix from $1,950 2008-12-19
Opera Browser HIGH 7.8
CVE-2008-5683

Unspecified vulnerability in Opera before 9.63 allows remote attackers to "reveal random data" via unknown vectors.

Fix: after 9.62
Fix from $1,950 2008-12-19
Opera HIGH 9.3
CVE-2008-5178EPSS 32%

Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overl…

No fix yet
Fix from $1,950 2008-11-20
Opera HIGH 9.3
CVE-2008-4794

Opera before 9.62 allows remote attackers to execute arbitrary commands via the History Search results page, a different vulnerability than CVE-2008-…

Fix: after 9.61
Fix from $1,950 2008-10-30
Opera Browser HIGH 9.3
CVE-2008-4694EPSS 10%

Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via…

Fix: after 9.60
Fix from $1,950 2008-10-23
Opera HIGH 9.3
CVE-2008-4695EPSS 6%

Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cac…

Fix: after 9.60
Fix from $1,950 2008-10-23
Opera Browser MEDIUM 5.8
CVE-2008-4698

Opera before 9.61 does not properly block scripts during preview of a news feed, which allows remote attackers to create arbitrary new feed subscript…

Fix: after 9.60
Fix from $1,600 2008-10-23
Opera Browser HIGH 10.0
CVE-2008-4292

Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL, which has unknown impact and attack vectors. NOT…

Fix: after 9.51
Fix from $1,950 2008-09-27
Opera HIGH 10.0
CVE-2008-4293

Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attackers to cause a denial of servic…

Fix: after 9.51
Fix from $1,950 2008-09-27
Opera Browser HIGH 8.8
CVE-2008-4197EPSS 6%

Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that conta…

Fix: 9.52+
Fix from $1,950 2008-09-27
Opera Browser MEDIUM 6.4
CVE-2008-4200

Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows remote attackers to change thi…

Fix: after 9.51
Fix from $1,600 2008-09-27
Opera Browser MEDIUM 5.0
CVE-2008-4195

Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows r…

Fix: after 9.51
Fix from $1,600 2008-09-27
Opera Browser MEDIUM 5.0
CVE-2008-4198

Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays a padlock icon and offers a security information …

Fix: after 9.51
Fix from $1,600 2008-09-27
Opera Browser MEDIUM 5.0
CVE-2008-4199

Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determin…

Fix: after 9.51
Fix from $1,600 2008-09-27
Opera MEDIUM 6.8
CVE-2008-3172

Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attacke…

Mitigation only
Fix from $1,600 2008-07-14
Opera HIGH 10.0
CVE-2008-3079

Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.

Fix: after 9.51
Fix from $1,950 2008-07-09
Opera Browser HIGH 7.8
CVE-2008-3078

Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized…

Fix: after 9.50
Fix from $1,950 2008-07-09
Opera Browser MEDIUM 5.0
CVE-2008-2714

Opera before 9.26 allows remote attackers to misrepresent web page addresses using "certain characters" that "cause the page address text to be mispl…

Fix: after 9.25
Fix from $1,600 2008-06-16
Opera Browser MEDIUM 5.0
CVE-2008-2715

Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images via HTML CANVAS elements that use the images as pat…

Fix: after 9.50
Fix from $1,600 2008-06-16
Opera Browser MEDIUM 5.0
CVE-2008-2716

Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trusted frames on the same parent page by modifying th…

Fix: 9.5+
Fix from $1,600 2008-06-16
Opera HIGH 9.3
CVE-2008-1761EPSS 8%

Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted newsfeed source, whi…

Fix: after 9.26
Fix from $1,950 2008-04-12