Vulnerabilities > CVE-2010-1728 - Resource Management Errors vulnerability in Opera Browser

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
opera
apple
microsoft
CWE-399
critical
nessus

Summary

Opera before 10.53 on Windows and Mac OS X does not properly handle a series of document modifications that occur asynchronously, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop, leading to attempted use of uninitialized memory. NOTE: this might overlap CVE-2006-6955.

Vulnerable Configurations

Part Description Count
Application
Opera
136
OS
Apple
1
OS
Microsoft
1

Common Weakness Enumeration (CWE)

Nessus

NASL familyWindows
NASL idOPERA_1053.NASL
descriptionThe version of Opera installed on the remote host is earlier than 10.53. Such versions are potentially affected by the following issue : - Multiple asynchronous calls to a script that modifies document contents can be abused to reference an uninitialized value, leading to an application crash or possibly allowing execution of arbitrary code. (953)
last seen2020-06-01
modified2020-06-02
plugin id46204
published2010-04-30
reporterThis script is Copyright (C) 2010-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/46204
titleOpera < 10.53 Asynchronous Content Modification Uninitialized Memory Access

Oval

accepted2013-12-23T04:00:06.168-05:00
classvulnerability
contributors
  • nameNikita MR
    organizationSecPod Technologies
  • nameJosh Turpin
    organizationSymantec Corporation
  • nameMaria Kedovskaya
    organizationALTX-SOFT
definition_extensions
commentOpera Browser is installed
ovaloval:org.mitre.oval:def:6482
description sequences in an infinite loop, leading to attempted use of uninitialized memory. NOTE: this might overlap CVE-2006-6955.
familywindows
idoval:org.mitre.oval:def:11927
statusaccepted
submitted2010-08-03T10:31:45.529
titleDenial of service in Opera before 10.53 due to failure to handle a series of document modifications that occur asynchronously.
version12