- EPSS 1.64%
- Veröffentlicht 16.03.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."
CVE-2008-5680
- EPSS 19.95%
- Veröffentlicht 19.12.2008 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-assisted remote attackers to execute arbitrary code via a long host name in a file: URL. NOTE: this ...
CVE-2008-5681
- EPSS 0.36%
- Veröffentlicht 19.12.2008 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera before 9.63 does not block unspecified "scripted URLs" during the feed preview, which allows remote attackers to read existing subscriptions and force subscriptions to arbitrary feed URLs.
CVE-2008-5682
- EPSS 0.48%
- Veröffentlicht 19.12.2008 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows remote attackers to inject arbitrary web script or HTML via built-in XSLT templates.
CVE-2008-5683
- EPSS 0.38%
- Veröffentlicht 19.12.2008 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Opera before 9.63 allows remote attackers to "reveal random data" via unknown vectors.
CVE-2008-4694
- EPSS 17.32%
- Veröffentlicht 23.10.2008 22:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a redirect that specifies a crafted URL.
CVE-2008-4697
- EPSS 0.79%
- Veröffentlicht 23.10.2008 22:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Fast Forward feature in Opera before 9.61, when a page is located in a frame, executes a javascript: URL in the context of the outermost page instead of the page that contains this URL, which allows remote attackers to conduct cross-site scriptin...
CVE-2008-4698
- EPSS 0.79%
- Veröffentlicht 23.10.2008 22:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera before 9.61 does not properly block scripts during preview of a news feed, which allows remote attackers to create arbitrary new feed subscriptions and read the contents of arbitrary feeds.
CVE-2008-4725
- EPSS 13.02%
- Veröffentlicht 23.10.2008 22:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a diffe...
- EPSS 0.68%
- Veröffentlicht 27.09.2008 10:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows remote attackers to trigger the display of an arbitrary address in a frame via unspecified use of web ...