Vulnerability index

Browse CVEs

208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opera Browser MEDIUM 5.0
CVE-2005-3946

Opera 8.50 allows remote attackers to cause a denial of service (crash) via a Java applet with a large string argument to the removeMember JNI method…

No fix yet
Fix from $1,600 2005-12-01
Opera Browser HIGH 7.5
CVE-2005-3750EPSS 6%

Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that anot…

Fix: 8.51+
Fix from $1,950 2005-11-22
Opera Browser MEDIUM 5.0
CVE-2005-3699

Opera Web Browser 8.50 and 8.0 through 8.0.2 allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trus…

No fix yet
Fix from $1,600 2005-11-21
Opera Browser HIGH 10.0
CVE-2005-3059

Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-rev…

Patch available
Fix from $1,950 2005-09-26
Opera Browser MEDIUM 5.0
CVE-2005-3041

Unspecified "drag-and-drop vulnerability" in Opera Web Browser before 8.50 on Windows allows "unintentional file uploads."

Fix: 8.50+
Fix from $1,600 2005-09-22
Opera Browser MEDIUM 5.0
CVE-2005-3006

The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attacker…

Fix: after 8.02
Fix from $1,600 2005-09-21
Opera Browser MEDIUM 5.1
CVE-2005-2407

A design error in Opera 8.01 and earlier allows user-assisted attackers to execute arbitrary code by overlaying a malicious new window above a file d…

Fix: after 8.01
Fix from $1,600 2005-08-01
Opera Browser MEDIUM 5.0
CVE-2005-2405

Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dia…

Patch available
Fix from $1,600 2005-08-01
Opera Browser MEDIUM 5.0
CVE-2005-2309

Opera 8.01 allows remote attackers to cause a denial of service (CPU consumption) via a crafted JPEG image, as demonstrated using random.jpg.

No fix yet
Fix from $1,600 2005-07-19
Opera Browser HIGH 7.5
CVE-2005-1475

The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on oth…

Fix: 8.01+
Fix from $1,950 2005-06-16
Opera Browser MEDIUM 6.8
CVE-2005-1669

Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via "javascript…

Fix: 8.01+
Fix from $1,600 2005-06-16
Opera Browser HIGH 7.2
CVE-2005-0457

Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious lib…

Fix: after 7.54
Fix from $1,950 2005-05-02
Opera Browser MEDIUM 5.0
CVE-2005-0235

The International Domain Name (IDN) support in Opera 7.54 allows remote attackers to spoof domain names using punycode encoded domain names that are …

Fix: after 7.54
Fix from $1,600 2005-05-02
Opera Browser HIGH 7.5
CVE-2005-1139

Opera 8 Beta 3, when using first-generation vetted digital certificates, displays the Organizational information of an SSL certificate, which is easi…

Patch available
Fix from $1,950 2005-04-14
Opera Browser MEDIUM 5.0
CVE-2005-0456

Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a down…

Fix: after 7.54
Fix from $1,600 2005-01-12
Opera Browser HIGH 7.5
CVE-2004-1157

Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a t…

Fix: after 7.54
Fix from $1,950 2005-01-10
Opera Browser MEDIUM 5.0
CVE-2004-1201

Opera 7.54 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code tha…

Fix: after 7.54
Fix from $1,600 2005-01-10
Opera Browser MEDIUM 5.0
CVE-2004-1810

The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size val…

Fix: after 7.23
Fix from $1,600 2004-12-31
Opera Browser MEDIUM 5.0
CVE-2004-2260

Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redir…

Fix: 7.50+
Fix from $1,600 2004-12-31
Opera Browser MEDIUM 5.0
CVE-2004-2570

Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from…

Fix: 7.54+
Fix from $1,600 2004-12-31
Opera Browser MEDIUM 5.0
CVE-2004-0872

Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domai…

Mitigation only
Fix from $1,600 2004-09-16
Opera Browser MEDIUM 5.0
CVE-2004-0537

Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to…

Fix: after 7.50
Fix from $1,600 2004-08-06
Opera Browser HIGH 7.5
CVE-2004-0717

Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another…

Mitigation only
Fix from $1,950 2004-07-27
Opera Browser HIGH 7.5
CVE-2003-0593

Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal s…

No fix yet
Fix from $1,950 2004-04-15
Opera Browser HIGH 9.3
CVE-2003-1388

Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.

Mitigation only
Fix from $1,950 2003-12-31
Opera Browser HIGH 7.5
CVE-2003-1387EPSS 15%

Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.

Patch available
Fix from $1,950 2003-12-31
Opera Browser MEDIUM 6.8
CVE-2003-1396EPSS 9%

Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary cod…

Fix: after 7.10
Fix from $1,600 2003-12-31
Opera Browser HIGH 7.5
CVE-2003-0870EPSS 15%

Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped charac…

Patch available
Fix from $1,950 2003-11-17