CVE-2007-5540
- EPSS 0.76%
- Veröffentlicht 18.10.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Opera before 9.24 allows remote attackers to overwrite functions on pages from other domains and bypass the same-origin policy via unknown vectors.
CVE-2007-5541
- EPSS 3.03%
- Veröffentlicht 18.10.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Opera before 9.24, when using an "external" newsgroup or e-mail client, allows remote attackers to execute arbitrary commands via unknown vectors.
CVE-2007-5276
- EPSS 0.24%
- Veröffentlicht 08.10.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera 9 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a sessi...
- EPSS 0.53%
- Veröffentlicht 18.09.2007 19:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.
CVE-2007-4367
- EPSS 8.73%
- Veröffentlicht 15.08.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual function call on an invalid pointer."
CVE-2007-3929
- EPSS 7.28%
- Veröffentlicht 21.07.2007 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the BitTorrent support in Opera before 9.22 allows user-assisted remote attackers to execute arbitrary code via a crafted header in a torrent file, which leaves a dangling pointer to an invalid object.
- EPSS 1.1%
- Veröffentlicht 17.07.2007 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera 9.21 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI with trailing whitespace, which prevents the beginning of the URI from being displayed.
CVE-2007-3142
- EPSS 0.72%
- Veröffentlicht 11.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Visual truncation vulnerability in Opera 9.21 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after 34 characters, as demonstrated by a phishing attack using HTTP Basic Au...
CVE-2007-2809
- EPSS 7.15%
- Veröffentlicht 22.05.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the transfer manager in Opera before 9.21 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted torrent file. NOTE: due to the lack of details, it is not clear if this is the same issue as CVE-2...
CVE-2007-2274
- EPSS 6.69%
- Veröffentlicht 25.04.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the original disclosure refers to this as a memory leak, but it is not certai...