opera records
311 published records for vendor opera.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 1%
- Pre-auth RCE
- 57
- With a fix record
- 1.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation30
- CWE-264 Permissions, Privileges, and Access Controls28
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-399 Resource Management Errors26
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor25
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer14
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
311 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2008-5178Proof of concept | Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI.opera · opera · CWE-119 | Critical9.3 | — | 31.5% | Nov 20, 2008 |
46Plan | CVE-2010-1349Proof of concept | Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which trigopera · opera browser · CWE-189 | Critical10.0 | — | 19.8% | Apr 12, 2010 |
44Plan | CVE-2015-4000Weaponized | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_Eopenssl · openssl · CWE-310 | Low3.7 | — | 99.9% | May 20, 2015 |
44Plan | CVE-2011-2628Proof of concept | Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial opera · opera browser · CWE-20 | Critical10.0 | — | 13.4% | Jul 1, 2011 |
43Plan | CVE-2007-5476No exploit | Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9.24 on Mac OS X, has unknown "Highly Sevadobe · flash player | Critical10.0 | — | 9.1% | Oct 17, 2007 |
42Plan | CVE-2013-1489No exploit | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windooracle · jdk | Critical10.0 | — | 7.6% | Jan 31, 2013 |
42Plan | CVE-2011-4684Proof of concept | Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corneopera · opera browser · CWE-310 | Critical10.0 | — | 5.7% | Dec 7, 2011 |
42Plan | CVE-2012-3561No exploit | Opera before 11.64 does not properly allocate memory for URL strings, which allows remote attackers to execute arbitrary code or cause a denopera · opera browser · CWE-119 | Critical10.0 | — | 5.2% | Jun 14, 2012 |
42Plan | CVE-2007-6521No exploit | Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.opera · opera browser · CWE-310 | Critical10.0 | — | 5.0% | Dec 24, 2007 |
41Plan | CVE-2008-4293No exploit | Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attackers to cause a denial opera · opera | Critical10.0 | — | 4.5% | Sep 27, 2008 |
41Plan | CVE-2008-3079No exploit | Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.opera · opera | Critical10.0 | — | 3.0% | Jul 8, 2008 |
41Plan | CVE-2009-0916No exploit | Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."opera · opera browser | Critical10.0 | — | 2.7% | Mar 16, 2009 |
41Plan | CVE-2009-4072No exploit | Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."opera · opera browser | Critical10.0 | — | 2.4% | Nov 24, 2009 |
41Plan | CVE-2010-2421No exploit | Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "hiopera · opera browser | Critical10.0 | — | 2.3% | Jun 22, 2010 |
41Plan | CVE-2005-3059No exploit | Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling ofopera · opera browser | Critical10.0 | — | 2.2% | Sep 26, 2005 |
41Plan | CVE-2012-4145No exploit | Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact opera · opera browser | Critical10.0 | — | 2.2% | Aug 6, 2012 |
41Plan | CVE-2010-4581No exploit | Unspecified vulnerability in Opera before 11.00 has unknown impact and attack vectors, related to "a high severity issue."opera · opera browser | Critical10.0 | — | 2.1% | Dec 21, 2010 |
41Plan | CVE-2011-2610No exploit | Unspecified vulnerability in Opera before 11.50 has unknown impact and attack vectors, related to a "moderately severe issue."opera · opera browser | Critical10.0 | — | 2.1% | Jul 1, 2011 |
41Plan | CVE-2010-4586No exploit | The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, poopera · opera browser · CWE-16 | Critical10.0 | — | 2.1% | Dec 21, 2010 |
41Plan | CVE-2011-4683No exploit | Unspecified vulnerability in Opera before 11.60 has unknown impact and attack vectors, related to a "moderately severe issue."opera · opera browser | Critical10.0 | — | 2.0% | Dec 7, 2011 |
41Plan | CVE-2008-4292No exploit | Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL, which has unknown impact and attack vectopera · opera browser · CWE-255 | Critical10.0 | — | 1.9% | Sep 27, 2008 |
41Plan | CVE-2013-3211No exploit | Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe issue."opera · opera browser | Critical10.0 | — | 1.7% | Apr 19, 2013 |
40Plan | CVE-2007-0126Proof of concept | Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bopera · opera browser · CWE-119 | Critical9.3 | — | 11.0% | Jan 8, 2007 |
40Plan | CVE-2008-4694Proof of concept | Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitraryopera · opera browser · CWE-59 | Critical9.3 | — | 9.8% | Oct 23, 2008 |
40Plan | CVE-2012-3559No exploit | Unspecified vulnerability in Opera before 12.00 on Mac OS X has unknown impact and attack vectors, related to a "moderate severity issue."opera · opera browser | Critical10.0 | — | 1.4% | Jun 14, 2012 |
- CVE-2008-517846Plan
Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI.
CriticalCVSS 9.3Proof of conceptEPSS 32%opera · operaNov 20, 2008
- CVE-2010-134946Plan
Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which trig
CriticalCVSS 10.0Proof of conceptEPSS 20%opera · opera browserApr 12, 2010
- CVE-2015-400044Plan
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_E
LowCVSS 3.7WeaponizedEPSS 100%openssl · opensslMay 20, 2015
- CVE-2011-262844Plan
Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial
CriticalCVSS 10.0Proof of conceptEPSS 13%opera · opera browserJul 1, 2011
- CVE-2007-547643Plan
Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9.24 on Mac OS X, has unknown "Highly Sev
CriticalCVSS 10.0No exploitEPSS 9%adobe · flash playerOct 17, 2007
- CVE-2013-148942Plan
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windo
CriticalCVSS 10.0No exploitEPSS 8%oracle · jdkJan 31, 2013
- CVE-2011-468442Plan
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corne
CriticalCVSS 10.0Proof of conceptEPSS 6%opera · opera browserDec 7, 2011
- CVE-2012-356142Plan
Opera before 11.64 does not properly allocate memory for URL strings, which allows remote attackers to execute arbitrary code or cause a den
CriticalCVSS 10.0No exploitEPSS 5%opera · opera browserJun 14, 2012
- CVE-2007-652142Plan
Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.
CriticalCVSS 10.0No exploitEPSS 5%opera · opera browserDec 24, 2007
- CVE-2008-429341Plan
Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attackers to cause a denial
CriticalCVSS 10.0No exploitEPSS 5%opera · operaSep 27, 2008
- CVE-2008-307941Plan
Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.
CriticalCVSS 10.0No exploitEPSS 3%opera · operaJul 8, 2008
- CVE-2009-091641Plan
Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."
CriticalCVSS 10.0No exploitEPSS 3%opera · opera browserMar 16, 2009
- CVE-2009-407241Plan
Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserNov 24, 2009
- CVE-2010-242141Plan
Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "hi
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserJun 22, 2010
- CVE-2005-305941Plan
Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserSep 26, 2005
- CVE-2012-414541Plan
Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserAug 6, 2012
- CVE-2010-458141Plan
Unspecified vulnerability in Opera before 11.00 has unknown impact and attack vectors, related to "a high severity issue."
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserDec 21, 2010
- CVE-2011-261041Plan
Unspecified vulnerability in Opera before 11.50 has unknown impact and attack vectors, related to a "moderately severe issue."
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserJul 1, 2011
- CVE-2010-458641Plan
The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, po
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserDec 21, 2010
- CVE-2011-468341Plan
Unspecified vulnerability in Opera before 11.60 has unknown impact and attack vectors, related to a "moderately severe issue."
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserDec 7, 2011
- CVE-2008-429241Plan
Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL, which has unknown impact and attack vect
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserSep 27, 2008
- CVE-2013-321141Plan
Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe issue."
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserApr 19, 2013
- CVE-2007-012640Plan
Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index b
CriticalCVSS 9.3Proof of conceptEPSS 11%opera · opera browserJan 8, 2007
- CVE-2008-469440Plan
Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary
CriticalCVSS 9.3Proof of conceptEPSS 10%opera · opera browserOct 23, 2008
- CVE-2012-355940Plan
Unspecified vulnerability in Opera before 12.00 on Mac OS X has unknown impact and attack vectors, related to a "moderate severity issue."
CriticalCVSS 10.0No exploitEPSS 1%opera · opera browserJun 14, 2012