Записи opera software
15 опубликованных записей вендора opera software.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 6,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2005-0233Эксплойта нет | The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain namozilla · camino | Высокая7,5 | — | 20,4 % | 8 февр. 2005 г. |
31Наблюдать | CVE-2002-1091Эксплойта нет | Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image withmozilla · mozilla | Высокая7,5 | — | 4,3 % | 4 окт. 2002 г. |
31Наблюдать | CVE-2002-0783Proof of concept | Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the locaopera software · opera web browser | Высокая7,5 | — | 2,8 % | 12 авг. 2002 г. |
30Наблюдать | CVE-2002-0243Эксплойта нет | Cross-site scripting vulnerability in Opera 6.0 and earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, wopera software · opera web browser | Высокая7,5 | — | 1,4 % | 29 мая 2002 г. |
28Наблюдать | CVE-2002-2311Эксплойта нет | Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key correspmicrosoft · internet explorer · CWE-264 | Средняя6,4 | — | 9,5 % | 31 дек. 2002 г. |
24Наблюдать | CVE-2002-2312Proof of concept | Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKopera software · opera | Средняя5,8 | — | 1,8 % | 31 дек. 2002 г. |
22Наблюдать | CVE-2001-1491Proof of concept | Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of imagopera software · opera web browser | Средняя5,0 | — | 7,0 % | 31 дек. 2001 г. |
22Наблюдать | CVE-2002-0898Proof of concept | Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input opera software · opera web browser | Средняя5,0 | — | 6,0 % | 4 окт. 2002 г. |
21Наблюдать | CVE-2001-0898Proof of concept | Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript thaopera software · opera web browser | Средняя5,0 | — | 3,1 % | 15 нояб. 2001 г. |
21Наблюдать | CVE-2001-1245Эксплойта нет | Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly wiopera software · opera web browser | Средняя5,0 | — | 2,4 % | 9 июл. 2001 г. |
21Наблюдать | CVE-2002-2332Эксплойта нет | Buffer overflow in Opera 6.01 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attribopera software · opera web browser · CWE-119 | Средняя5,0 | — | 1,8 % | 31 дек. 2002 г. |
20Наблюдать | CVE-1999-1283Эксплойта нет | Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.opera software · opera web browser | Средняя5,0 | — | 1,3 % | 14 авг. 1998 г. |
18Наблюдать | CVE-2002-0270Эксплойта нет | Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIMEopera software · opera web browser · CWE-79 | Средняя4,3 | — | 4,7 % | 29 мая 2002 г. |
18Наблюдать | CVE-2002-2358Proof of concept | Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitropera software · opera web browser · CWE-79 | Средняя4,3 | — | 1,7 % | 31 дек. 2002 г. |
17Наблюдать | CVE-2002-2414Эксплойта нет | Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certifsquid · squid | Средняя4,3 | — | 1,2 % | 31 дек. 2002 г. |
- CVE-2005-023336Наблюдать
The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain na
ВысокаяCVSS 7,5Эксплойта нетEPSS 20 %mozilla · camino8 февр. 2005 г.
- CVE-2002-109131Наблюдать
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mozilla · mozilla4 окт. 2002 г.
- CVE-2002-078331Наблюдать
Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the loca
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %opera software · opera web browser12 авг. 2002 г.
- CVE-2002-024330Наблюдать
Cross-site scripting vulnerability in Opera 6.0 and earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, w
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opera software · opera web browser29 мая 2002 г.
- CVE-2002-231128Наблюдать
Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresp
СредняяCVSS 6,4Эксплойта нетEPSS 10 %microsoft · internet explorer31 дек. 2002 г.
- CVE-2002-231224Наблюдать
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlK
СредняяCVSS 5,8Proof of conceptEPSS 2 %opera software · opera31 дек. 2002 г.
- CVE-2001-149122Наблюдать
Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of imag
СредняяCVSS 5,0Proof of conceptEPSS 7 %opera software · opera web browser31 дек. 2001 г.
- CVE-2002-089822Наблюдать
Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input
СредняяCVSS 5,0Proof of conceptEPSS 6 %opera software · opera web browser4 окт. 2002 г.
- CVE-2001-089821Наблюдать
Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript tha
СредняяCVSS 5,0Proof of conceptEPSS 3 %opera software · opera web browser15 нояб. 2001 г.
- CVE-2001-124521Наблюдать
Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly wi
СредняяCVSS 5,0Эксплойта нетEPSS 2 %opera software · opera web browser9 июл. 2001 г.
- CVE-2002-233221Наблюдать
Buffer overflow in Opera 6.01 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attrib
СредняяCVSS 5,0Эксплойта нетEPSS 2 %opera software · opera web browser31 дек. 2002 г.
- CVE-1999-128320Наблюдать
Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.
СредняяCVSS 5,0Эксплойта нетEPSS 1 %opera software · opera web browser14 авг. 1998 г.
- CVE-2002-027018Наблюдать
Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME
СредняяCVSS 4,3Эксплойта нетEPSS 5 %opera software · opera web browser29 мая 2002 г.
- CVE-2002-235818Наблюдать
Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitr
СредняяCVSS 4,3Proof of conceptEPSS 2 %opera software · opera web browser31 дек. 2002 г.
- CVE-2002-241417Наблюдать
Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certif
СредняяCVSS 4,3Эксплойта нетEPSS 1 %squid · squid31 дек. 2002 г.