Show filters
166 Total Results
Displaying 161-166 of 166
Sort by:
Attacker Value
Unknown
CVE-2006-6955
Disclosure Date: January 29, 2007 (last updated October 04, 2023)
Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
0
Attacker Value
Unknown
CVE-2007-0127
Disclosure Date: January 09, 2007 (last updated October 04, 2023)
The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.
0
Attacker Value
Unknown
CVE-2006-1834
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check. NOTE: a sign extension problem makes the attack easier with shorter strings.
0
Attacker Value
Unknown
CVE-2005-3006
Disclosure Date: September 21, 2005 (last updated February 22, 2025)
The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.
0
Attacker Value
Unknown
CVE-2004-0872
Disclosure Date: September 16, 2004 (last updated February 22, 2025)
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
0
Attacker Value
Unknown
CVE-2004-0717
Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
0