Show filters
294 Total Results
Displaying 11-20 of 294
Sort by:
Attacker Value
Unknown
CVE-2013-3210
Disclosure Date: April 19, 2013 (last updated October 05, 2023)
Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.
0
Attacker Value
Unknown
CVE-2013-1618
Disclosure Date: February 08, 2013 (last updated October 05, 2023)
The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
0
Attacker Value
Unknown
CVE-2013-1639
Disclosure Date: February 08, 2013 (last updated October 05, 2023)
Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that triggers a CORS request.
0
Attacker Value
Unknown
CVE-2013-1638
Disclosure Date: February 08, 2013 (last updated October 05, 2023)
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
0
Attacker Value
Unknown
CVE-2013-1637
Disclosure Date: February 08, 2013 (last updated October 05, 2023)
Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.
0
Attacker Value
Unknown
CVE-2012-6465
Disclosure Date: January 02, 2013 (last updated October 05, 2023)
Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image.
0
Attacker Value
Unknown
CVE-2012-6462
Disclosure Date: January 02, 2013 (last updated October 05, 2023)
Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request.
0
Attacker Value
Unknown
CVE-2012-6460
Disclosure Date: January 02, 2013 (last updated October 05, 2023)
Opera before 11.67 and 12.x before 12.02 allows remote attackers to cause truncation of a dialog, and possibly trigger downloading and execution of arbitrary programs, via a crafted web site.
0
Attacker Value
Unknown
CVE-2012-6466
Disclosure Date: January 02, 2013 (last updated October 05, 2023)
Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from process memory by using a crafted image as the fill pattern for a canvas.
0
Attacker Value
Unknown
CVE-2012-6467
Disclosure Date: January 02, 2013 (last updated October 05, 2023)
Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site, as exploited in the wild in November 2012.
0