- EPSS 1.14%
- Published 16.09.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cros...
- EPSS 0.65%
- Published 06.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.
CVE-2004-0717
- EPSS 0.62%
- Published 27.07.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability...
CVE-2004-0473
- EPSS 1.14%
- Published 07.07.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) t...
CVE-2003-0593
- EPSS 0.15%
- Published 15.04.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a...
CVE-2004-2083
- EPSS 1.14%
- Published 11.02.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."
CVE-2003-1387
- EPSS 9.99%
- Published 31.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.
CVE-2003-1388
- EPSS 2.33%
- Published 31.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.
CVE-2003-1396
- EPSS 3.83%
- Published 31.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.
CVE-2003-1397
- EPSS 5.16%
- Published 31.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.