opera software records
15 published records for vendor opera software.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 6.7%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2005-0233No exploit | The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain namozilla · camino | High7.5 | — | 20.4% | Feb 8, 2005 |
31Monitor | CVE-2002-1091No exploit | Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image withmozilla · mozilla | High7.5 | — | 4.3% | Oct 4, 2002 |
31Monitor | CVE-2002-0783Proof of concept | Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the locaopera software · opera web browser | High7.5 | — | 2.8% | Aug 12, 2002 |
30Monitor | CVE-2002-0243No exploit | Cross-site scripting vulnerability in Opera 6.0 and earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, wopera software · opera web browser | High7.5 | — | 1.4% | May 29, 2002 |
28Monitor | CVE-2002-2311No exploit | Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key correspmicrosoft · internet explorer · CWE-264 | Medium6.4 | — | 9.5% | Dec 31, 2002 |
24Monitor | CVE-2002-2312Proof of concept | Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKopera software · opera | Medium5.8 | — | 1.8% | Dec 31, 2002 |
22Monitor | CVE-2001-1491Proof of concept | Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of imagopera software · opera web browser | Medium5.0 | — | 7.0% | Dec 31, 2001 |
22Monitor | CVE-2002-0898Proof of concept | Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input opera software · opera web browser | Medium5.0 | — | 6.0% | Oct 4, 2002 |
21Monitor | CVE-2001-0898Proof of concept | Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript thaopera software · opera web browser | Medium5.0 | — | 3.1% | Nov 15, 2001 |
21Monitor | CVE-2001-1245No exploit | Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly wiopera software · opera web browser | Medium5.0 | — | 2.4% | Jul 9, 2001 |
21Monitor | CVE-2002-2332No exploit | Buffer overflow in Opera 6.01 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attribopera software · opera web browser · CWE-119 | Medium5.0 | — | 1.8% | Dec 31, 2002 |
20Monitor | CVE-1999-1283No exploit | Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.opera software · opera web browser | Medium5.0 | — | 1.3% | Aug 14, 1998 |
18Monitor | CVE-2002-0270No exploit | Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIMEopera software · opera web browser · CWE-79 | Medium4.3 | — | 4.7% | May 29, 2002 |
18Monitor | CVE-2002-2358Proof of concept | Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitropera software · opera web browser · CWE-79 | Medium4.3 | — | 1.7% | Dec 31, 2002 |
17Monitor | CVE-2002-2414No exploit | Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certifsquid · squid | Medium4.3 | — | 1.2% | Dec 31, 2002 |
- CVE-2005-023336Monitor
The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain na
HighCVSS 7.5No exploitEPSS 20%mozilla · caminoFeb 8, 2005
- CVE-2002-109131Monitor
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with
HighCVSS 7.5No exploitEPSS 4%mozilla · mozillaOct 4, 2002
- CVE-2002-078331Monitor
Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the loca
HighCVSS 7.5Proof of conceptEPSS 3%opera software · opera web browserAug 12, 2002
- CVE-2002-024330Monitor
Cross-site scripting vulnerability in Opera 6.0 and earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, w
HighCVSS 7.5No exploitEPSS 1%opera software · opera web browserMay 29, 2002
- CVE-2002-231128Monitor
Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresp
MediumCVSS 6.4No exploitEPSS 10%microsoft · internet explorerDec 31, 2002
- CVE-2002-231224Monitor
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlK
MediumCVSS 5.8Proof of conceptEPSS 2%opera software · operaDec 31, 2002
- CVE-2001-149122Monitor
Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of imag
MediumCVSS 5.0Proof of conceptEPSS 7%opera software · opera web browserDec 31, 2001
- CVE-2002-089822Monitor
Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input
MediumCVSS 5.0Proof of conceptEPSS 6%opera software · opera web browserOct 4, 2002
- CVE-2001-089821Monitor
Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript tha
MediumCVSS 5.0Proof of conceptEPSS 3%opera software · opera web browserNov 15, 2001
- CVE-2001-124521Monitor
Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly wi
MediumCVSS 5.0No exploitEPSS 2%opera software · opera web browserJul 9, 2001
- CVE-2002-233221Monitor
Buffer overflow in Opera 6.01 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attrib
MediumCVSS 5.0No exploitEPSS 2%opera software · opera web browserDec 31, 2002
- CVE-1999-128320Monitor
Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.
MediumCVSS 5.0No exploitEPSS 1%opera software · opera web browserAug 14, 1998
- CVE-2002-027018Monitor
Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME
MediumCVSS 4.3No exploitEPSS 5%opera software · opera web browserMay 29, 2002
- CVE-2002-235818Monitor
Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitr
MediumCVSS 4.3Proof of conceptEPSS 2%opera software · opera web browserDec 31, 2002
- CVE-2002-241417Monitor
Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certif
MediumCVSS 4.3No exploitEPSS 1%squid · squidDec 31, 2002