Vulnerabilities > Opera > Opera Browser > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-09-27 CVE-2008-4195 Permissions, Privileges, and Access Controls vulnerability in Opera Browser
Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows remote attackers to trigger the display of an arbitrary address in a frame via unspecified use of web script.
network
low complexity
opera CWE-264
5.0
2008-06-16 CVE-2008-2716 Improper Restriction of Rendered UI Layers or Frames vulnerability in Opera Browser
Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trusted frames on the same parent page by modifying the location, which can facilitate phishing attacks.
network
low complexity
opera CWE-1021
5.0
2008-06-16 CVE-2008-2715 Information Exposure vulnerability in Opera Browser
Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images via HTML CANVAS elements that use the images as patterns.
network
low complexity
opera CWE-200
5.0
2008-06-16 CVE-2008-2714 Multiple Security vulnerability in Opera Web Browser 9.27
Opera before 9.26 allows remote attackers to misrepresent web page addresses using "certain characters" that "cause the page address text to be misplaced."
network
low complexity
opera
5.0
2008-02-29 CVE-2008-1082 Cross-Site Scripting vulnerability in Opera Browser
Opera before 9.26 allows remote attackers to "bypass sanitization filters" and conduct cross-site scripting (XSS) attacks via crafted attribute values in an XML document, which are not properly handled during DOM presentation.
network
opera CWE-79
4.3
2008-02-29 CVE-2008-1081 Code Injection vulnerability in Opera Browser
Opera before 9.26 allows user-assisted remote attackers to execute arbitrary script via images that contain custom comments, which are treated as script when the user displays the image properties.
network
opera CWE-94
6.8
2008-02-29 CVE-2008-1080 Improper Input Validation vulnerability in Opera Browser
Opera before 9.26 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename into a file input.
network
opera CWE-20
6.8
2007-12-24 CVE-2007-6522 Cross-Site Scripting vulnerability in Opera Browser
The rich text editing functionality in Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks by using designMode to modify contents of pages in other domains.
network
opera CWE-79
4.3
2007-12-24 CVE-2007-6520 Cross-Site Scripting vulnerability in Opera Browser
Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks via unknown vectors related to plug-ins.
network
opera CWE-79
4.3
2007-10-08 CVE-2007-5276 Unspecified vulnerability in Opera Browser 9.0
Opera 9 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a session on port 80.
network
opera
4.3