Opera

Opera Browser

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.32%
  • Veröffentlicht 20.07.2009 18:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera, possibly 9.64 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 07.07.2009 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the conte...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 15.06.2009 19:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying...

  • EPSS 0.27%
  • Veröffentlicht 15.06.2009 19:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify ...

  • EPSS 0.27%
  • Veröffentlicht 15.06.2009 19:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that re...

  • EPSS 0.14%
  • Veröffentlicht 15.06.2009 19:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site du...

  • EPSS 0.24%
  • Veröffentlicht 11.05.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on access...

Exploit
  • EPSS 16.57%
  • Veröffentlicht 02.04.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected.

  • EPSS 10.24%
  • Veröffentlicht 16.03.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption.

  • EPSS 1.26%
  • Veröffentlicht 16.03.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Opera before 9.64 allows remote attackers to conduct cross-domain scripting attacks via unspecified vectors related to plug-ins.