Show filters
294 Total Results
Displaying 171-180 of 294
Sort by:
Attacker Value
Unknown
CVE-2009-2540
Disclosure Date: July 20, 2009 (last updated February 02, 2024)
Opera, possibly 9.64 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
0
Attacker Value
Unknown
CVE-2009-2351
Disclosure Date: July 07, 2009 (last updated October 04, 2023)
Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.
0
Attacker Value
Unknown
CVE-2009-2059
Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
0
Attacker Value
Unknown
CVE-2009-2063
Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
0
Attacker Value
Unknown
CVE-2009-2067
Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
0
Attacker Value
Unknown
CVE-2009-2070
Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.
0
Attacker Value
Unknown
CVE-2009-1599
Disclosure Date: May 11, 2009 (last updated October 04, 2023)
Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content."
0
Attacker Value
Unknown
CVE-2009-1234
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected.
0
Attacker Value
Unknown
CVE-2009-0916
Disclosure Date: March 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."
0
Attacker Value
Unknown
CVE-2009-0914
Disclosure Date: March 16, 2009 (last updated October 04, 2023)
Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption.
0