Opera / Opera
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-6159 | URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain ci… | MEDIUM | 6.1 | Dec 23, 2020 |
| CVE-2019-12278 | Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several… | MEDIUM | 4.3 | Mar 12, 2020 |
| CVE-2019-19788 | Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe i… | MEDIUM | 5.5 | Dec 18, 2019 |
| CVE-2016-7152 | HTTPS: HEIST attack allows attackers to sniff TLS encrypted HTTP traffic | MEDIUM | 5.3 | Sep 6, 2016 |
| CVE-2010-5227 | Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working direc… | MEDIUM | 6.9 | Sep 7, 2012 |
| CVE-2009-2068 | Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary w… | MEDIUM | 5.8 | Jun 15, 2009 |
| CVE-2008-5679 | The HTML parsing engine in Opera before 9.63 allows remote attackers to execute arbitrary code via crafted web pages that trigger an invalid pointer calculatio… | HIGH | 9.3 | Dec 19, 2008 |
| CVE-2008-5428 | Opera 9.51 on Windows XP does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-… | MEDIUM | 4.3 | Dec 11, 2008 |
| CVE-2008-5178 | Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008… | HIGH | 9.3 | Nov 20, 2008 |
| CVE-2008-4795 | The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitr… | MEDIUM | 4.3 | Oct 30, 2008 |
| CVE-2008-4794 | Opera before 9.62 allows remote attackers to execute arbitrary commands via the History Search results page, a different vulnerability than CVE-2008-4696. | HIGH | 9.3 | Oct 30, 2008 |
| CVE-2008-4696 | Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identi… | MEDIUM | 4.3 | Oct 23, 2008 |
| CVE-2008-4695 | Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cached Java a… | HIGH | 9.3 | Oct 23, 2008 |
| CVE-2008-4293 | Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attackers to cause a denial of service (crash)… | HIGH | 10.0 | Sep 27, 2008 |
| CVE-2008-3172 | Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attackers to perf… | MEDIUM | 6.8 | Jul 14, 2008 |
| CVE-2003-1561 | Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially s… | MEDIUM | 4.3 | Jul 14, 2008 |
| CVE-2008-3079 | Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors. | HIGH | 10.0 | Jul 9, 2008 |
| CVE-2008-1764 | Unspecified vulnerability in Opera before 9.27 has unknown impact and attack vectors related to "keyboard handling of password inputs." | HIGH | 9.3 | Apr 12, 2008 |
| CVE-2008-1761 | Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted newsfeed source, which trigger… | HIGH | 9.3 | Apr 12, 2008 |
| CVE-2002-2414 | Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site a… | MEDIUM | 4.3 | Nov 1, 2007 |
| CVE-2002-2312 | Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shi… | MEDIUM | 5.8 | Oct 26, 2007 |
Showing 1 to 21 of 21 CVEs