Vulnerabilities (CVE)

Filtered by vendor Opera Subscribe
Total 311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-4581 1 Opera 1 Opera Browser 2011-01-22 10.0 HIGH N/A
Unspecified vulnerability in Opera before 11.00 has unknown impact and attack vectors, related to "a high severity issue."
CVE-2010-4585 1 Opera 1 Opera Browser 2011-01-22 5.0 MEDIUM N/A
Unspecified vulnerability in the auto-update functionality in Opera before 11.00 allows remote attackers to cause a denial of service (application crash) by triggering an Opera Unite update.
CVE-2010-4584 1 Opera 1 Opera Browser 2011-01-22 2.6 LOW N/A
Opera before 11.00, when Opera Turbo is used, does not properly present information about problematic X.509 certificates on https web sites, which might make it easier for remote attackers to spoof trusted content via a crafted web site.
CVE-2010-4582 1 Opera 1 Opera Browser 2011-01-22 5.0 MEDIUM N/A
Opera before 11.00 does not properly handle security policies during updates to extensions, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.
CVE-2010-4586 1 Opera 1 Opera Browser 2011-01-22 10.0 HIGH N/A
The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, possibly a related issue to CVE-2010-4508.
CVE-2010-4583 1 Opera 1 Opera Browser 2011-01-22 2.6 LOW N/A
Opera before 11.00, when Opera Turbo is enabled, does not display a page's security indication, which makes it easier for remote attackers to spoof trusted content via a crafted web site.
CVE-2010-4587 2 Microsoft, Opera 2 Windows, Opera Browser 2011-01-12 9.3 HIGH N/A
Opera before 11.00 on Windows does not properly implement the Insecure Third Party Module warning message, which might make it easier for user-assisted remote attackers to have an unspecified impact via a crafted module.
CVE-2010-0653 1 Opera 1 Opera Browser 2010-09-21 4.3 MEDIUM N/A
Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
CVE-2010-1310 1 Opera 1 Opera Browser 2010-04-09 5.0 MEDIUM N/A
Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other pages.
CVE-2003-1561 1 Opera 1 Opera 2009-01-29 4.3 MEDIUM N/A
Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
CVE-2007-4944 1 Opera 1 Opera Browser 2008-11-15 5.0 MEDIUM N/A
The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.