Opera / Opera Browser
282 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-18913 | Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a… | HIGH | 7.8 | Mar 21, 2019 |
| CVE-2018-6608 | In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com),… | MEDIUM | 4.3 | Mar 28, 2018 |
| CVE-2016-4075 | Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL. | MEDIUM | 6.1 | Apr 21, 2017 |
| CVE-2016-6908 | Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of… | MEDIUM | 6.1 | Jan 26, 2017 |
| CVE-2016-7153 | HTTP/2: HEIST attack allows attackers to sniff TLS encrypted HTTP/2 traffic | MEDIUM | 5.3 | Sep 6, 2016 |
| CVE-2015-4000 | LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks | LOW | 3.7 | May 21, 2015 |
| CVE-2014-1870 | Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-drop operation. | MEDIUM | 4.3 | Feb 6, 2014 |
| CVE-2014-0815 | The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by readin… | MEDIUM | 4.3 | Feb 6, 2014 |
| CVE-2013-4705 | Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows remote attackers to inject arbitrary web script or HTML by leveraging UTF-8 encoding. | MEDIUM | 4.3 | Sep 13, 2013 |
| CVE-2013-3211 | Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe issue." | HIGH | 10.0 | Apr 19, 2013 |
| CVE-2013-3210 | Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging… | MEDIUM | 5.0 | Apr 19, 2013 |
| CVE-2013-1618 | The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed… | MEDIUM | 4.0 | Feb 8, 2013 |
| CVE-2013-1639 | Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a craft… | MEDIUM | 6.8 | Feb 8, 2013 |
| CVE-2013-1638 | Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document. | HIGH | 9.3 | Feb 8, 2013 |
| CVE-2013-1637 | Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events. | HIGH | 9.3 | Feb 8, 2013 |
| CVE-2012-6472 | Opera before 12.12 on UNIX uses weak permissions for the profile directory, which allows local users to obtain sensitive information by reading a (1) cache fil… | MEDIUM | 4.6 | Jan 2, 2013 |
| CVE-2012-6471 | Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests. | MEDIUM | 5.0 | Jan 2, 2013 |
| CVE-2012-6470 | Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memo… | HIGH | 9.3 | Jan 2, 2013 |
| CVE-2012-6469 | Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page. | MEDIUM | 5.0 | Jan 2, 2013 |
| CVE-2012-6468 | Heap-based buffer overflow in Opera before 12.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long… | HIGH | 9.3 | Jan 2, 2013 |
| CVE-2012-6467 | Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for remote attackers… | MEDIUM | 4.3 | Jan 2, 2013 |
| CVE-2012-6466 | Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from… | MEDIUM | 5.0 | Jan 2, 2013 |
| CVE-2012-6465 | Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image. | HIGH | 9.3 | Jan 2, 2013 |
| CVE-2012-6464 | Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript code that… | MEDIUM | 4.3 | Jan 2, 2013 |
| CVE-2012-6463 | Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an unspecif… | MEDIUM | 4.3 | Jan 2, 2013 |
Showing 1 to 25 of 282 CVEs