Show filters
139 Total Results
Displaying 131-139 of 139
Sort by:
Attacker Value
Unknown
CVE-2009-4072
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."
0
Attacker Value
Unknown
CVE-2009-4071
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Opera before 10.10, when exception stacktraces are enabled, places scripting error messages from a web site into variables that can be read by a different web site, which allows remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-3265
Disclosure Date: September 18, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as "scripted content." NOTE: the vendor reportedly considers this behavior a "design feature," not a vulnerability.
0
Attacker Value
Unknown
CVE-2009-3266
Disclosure Date: September 18, 2009 (last updated October 04, 2023)
Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."
0
Attacker Value
Unknown
CVE-2009-3044
Disclosure Date: September 02, 2009 (last updated October 04, 2023)
Opera before 10.00 does not properly handle a (1) '\0' character or (2) invalid wildcard character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
0
Attacker Value
Unknown
CVE-2009-3048
Disclosure Date: September 02, 2009 (last updated October 04, 2023)
Opera before 10.00 on Linux, Solaris, and FreeBSD does not properly implement the "INPUT TYPE=file" functionality, which allows remote attackers to trick a user into uploading an unintended file via vectors involving a "dropped file."
0
Attacker Value
Unknown
CVE-2009-3013
Disclosure Date: August 31, 2009 (last updated October 04, 2023)
Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site.
0
Attacker Value
Unknown
CVE-2009-2351
Disclosure Date: July 07, 2009 (last updated October 04, 2023)
Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.
0
Attacker Value
Unknown
CVE-2006-6955
Disclosure Date: January 29, 2007 (last updated October 04, 2023)
Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
0