Show filters
294 Total Results
Displaying 271-280 of 294
Sort by:
Attacker Value
Unknown
CVE-2004-0872
Disclosure Date: September 16, 2004 (last updated February 22, 2025)
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
0
Attacker Value
Unknown
CVE-2004-0537
Disclosure Date: August 06, 2004 (last updated October 04, 2023)
Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.
0
Attacker Value
Unknown
CVE-2004-0717
Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
0
Attacker Value
Unknown
CVE-2004-0473
Disclosure Date: July 07, 2004 (last updated February 22, 2025)
Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the "-f" option on Windows XP or (2) the "-n" option on Linux.
0
Attacker Value
Unknown
CVE-2003-0593
Disclosure Date: April 15, 2004 (last updated February 22, 2025)
Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
0
Attacker Value
Unknown
CVE-2004-2083
Disclosure Date: February 11, 2004 (last updated October 03, 2023)
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."
0
Attacker Value
Unknown
CVE-2003-1387
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.
0
Attacker Value
Unknown
CVE-2003-1420
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.
0
Attacker Value
Unknown
CVE-2003-1388
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.
0
Attacker Value
Unknown
CVE-2003-1397
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.
0