MEDIUM
Opera before 10.61 does not properly suppress clicks on download dialogs that became visible after a recent tab change, which allows remote attackers to conduct clickjacking attacks, and consequently execute arbitrary code, via vectors involving (1) closing a tab or (2) hiding a tab, a related issue to CVE-2005-2407
Published Aug 16, 2010
6.8
MEDIUMCVSS 2.0
EPSS 3.36%
Description
Opera before 10.61 does not properly suppress clicks on download dialogs that became visible after a recent tab change, which allows remote attackers to conduct clickjacking attacks, and consequently execute arbitrary code, via vectors involving (1) closing a tab or (2) hiding a tab, a related issue to CVE-2005-2407.
Affected products
No data.
OR
- ≤ 10.60
- 1.00
- 2.00
- 2.10
- 2.10
- 2.10
- 2.10
- 2.12
- 3.00
- 3.00
- 3.10
- 3.21
- 3.50
- 3.51
- 3.60
- 3.61
- 3.62
- 3.62
- 4.00
- 4.00
- 4.00
- 4.00
- 4.00
- 4.00
- 4.01
- 4.02
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.02
- 5.10
- 5.11
- 5.12
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.1
- 6.01
- 6.1
- 6.02
- 6.03
- 6.04
- 6.05
- 6.06
- 6.11
- 6.12
- 7.0
- 7.0
- 7.0
- 7.0
- 7.01
- 7.02
- 7.03
- 7.10
- 7.10
- 7.11
- 7.11
- 7.20
- 7.20
- 7.21
- 7.22
- 7.23
- 7.50
- 7.50
- 7.51
- 7.52
- 7.53
- 7.54
- 7.54
- 7.54
- 7.60
- 8.0
- 8.0
- 8.0
- 8.0
- 8.01
- 8.02
- 8.50
- 8.51
- 8.52
- 8.53
- 8.54
- 9.0
- 9.0
- 9.0
- 9.01
- 9.02
- 9.10
- 9.12
- 9.20
- 9.20
- 9.21
- 9.22
- 9.23
- 9.24
- 9.25
- 9.26
- 9.27
- 9.50
- 9.50
- 9.50
- 9.51
- 9.52
- 9.60
- 9.60
- 9.61
- 9.62
- 9.63
- 9.64
- 10.00
- 10.00
- 10.00
- 10.00
- 10.00
- 10.01
- 10.10
- 10.10
- 10.11
- 10.20
- 10.50
- 10.50
- 10.50
- 10.51
- 10.52
- 10.53
- 10.54
- 10.60
- 10.60
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://secunia.com/secunia_research/2010-110/ x_refsource_MISCVendor Advisory
- http://www.opera.com/docs/changelogs/mac/1061/ x_refsource_CONFIRM
- http://www.opera.com/docs/changelogs/unix/1061/ x_refsource_CONFIRM
- http://www.opera.com/docs/changelogs/windows/1061/ x_refsource_CONFIRM
- http://www.opera.com/support/kb/view/967/ x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/archive/1/513040/100/0/threaded mailing-listx_refsource_BUGTRAQ
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-2580 Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12084 vdb-entrysignaturex_refsource_OVAL
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/secunia_research/2010-110/ | x_refsource_MISCVendor Advisory | |
| http://www.opera.com/docs/changelogs/mac/1061/ | x_refsource_CONFIRM | |
| http://www.opera.com/docs/changelogs/unix/1061/ | x_refsource_CONFIRM | |
| http://www.opera.com/docs/changelogs/windows/1061/ | x_refsource_CONFIRM | |
| http://www.opera.com/support/kb/view/967/ | x_refsource_CONFIRMVendor Advisory | |
| http://www.securityfocus.com/archive/1/513040/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-2580 | Advisory | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12084 | vdb-entrysignaturex_refsource_OVAL |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published Aug 16, 2010
Updated Aug 7, 2024
Reserved Jul 1, 2010
Link CVE-2010-2576
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-2580 Assigner flexera
Published Aug 16, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-2580