CVE-2007-2022
- EPSS 15.37%
- Veröffentlicht 13.04.2007 18:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.
CVE-2007-1737
- EPSS 0.13%
- Veröffentlicht 28.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera 9.10 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.
CVE-2007-1563
- EPSS 10.07%
- Veröffentlicht 21.03.2007 19:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in ...
- EPSS 18.26%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followe...
CVE-2007-1115
- EPSS 0.8%
- Veröffentlicht 26.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The child frames in Opera 9 before 9.20 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as dem...
- EPSS 0.28%
- Veröffentlicht 07.02.2007 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name, as demonstrated by the "." and "/" characters, which is not caught by the blacklist filter.
CVE-2007-0802
- EPSS 0.97%
- Veröffentlicht 07.02.2007 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist ...
CVE-2006-6955
- EPSS 0.53%
- Veröffentlicht 29.01.2007 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
CVE-2007-0126
- EPSS 14.96%
- Veröffentlicht 09.01.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker.
CVE-2007-0127
- EPSS 10.08%
- Veröffentlicht 09.01.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request...