Vulnerabilities
Vulnerable Software
Opera:  >> Opera Browser  >> 10.60  Security Vulnerabilities
Opera before 11.01 does not properly implement Wireless Application Protocol (WAP) dropdown lists, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted WAP document.
CVSS Score
4.3
EPSS Score
0.016
Published
2011-01-31
The Cascading Style Sheets (CSS) Extensions for XML implementation in Opera before 11.01 recognizes links to javascript: URLs in the -o-link property, which makes it easier for remote attackers to bypass CSS filtering via a crafted URL.
CVSS Score
4.3
EPSS Score
0.003
Published
2011-01-31
Integer truncation error in opera.dll in Opera before 11.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML form with a select element that contains a large number of children.
CVSS Score
9.3
EPSS Score
0.116
Published
2011-01-31
The downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers to execute arbitrary code via a crafted web site that hosts an executable file.
CVSS Score
7.6
EPSS Score
0.038
Published
2011-01-31
Opera before 11.00 does not properly constrain dialogs to appear on top of rendered documents, which makes it easier for remote attackers to trick users into interacting with a crafted web site that spoofs the (1) security information dialog or (2) download dialog.
CVSS Score
5.0
EPSS Score
0.007
Published
2010-12-22
Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive information via an input field that has the same name as an input field on a previously visited web site.
CVSS Score
5.0
EPSS Score
0.007
Published
2010-12-22
Unspecified vulnerability in Opera before 11.00 has unknown impact and attack vectors, related to "a high severity issue."
CVSS Score
10.0
EPSS Score
0.005
Published
2010-12-22
Opera before 11.00 does not properly handle security policies during updates to extensions, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.
CVSS Score
5.0
EPSS Score
0.003
Published
2010-12-22
Opera before 11.00, when Opera Turbo is enabled, does not display a page's security indication, which makes it easier for remote attackers to spoof trusted content via a crafted web site.
CVSS Score
2.6
EPSS Score
0.003
Published
2010-12-22
Opera before 11.00, when Opera Turbo is used, does not properly present information about problematic X.509 certificates on https web sites, which might make it easier for remote attackers to spoof trusted content via a crafted web site.
CVSS Score
2.6
EPSS Score
0.002
Published
2010-12-22


Contact Us

Shodan ® - All rights reserved