Vulnerabilities > Opera > Opera Browser > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-09-27 | CVE-2008-4195 | Permissions, Privileges, and Access Controls vulnerability in Opera Browser Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows remote attackers to trigger the display of an arbitrary address in a frame via unspecified use of web script. | 5.0 |
2008-06-16 | CVE-2008-2716 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Opera Browser Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trusted frames on the same parent page by modifying the location, which can facilitate phishing attacks. | 5.0 |
2008-06-16 | CVE-2008-2715 | Information Exposure vulnerability in Opera Browser Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images via HTML CANVAS elements that use the images as patterns. | 5.0 |
2008-06-16 | CVE-2008-2714 | Multiple Security vulnerability in Opera Web Browser 9.27 Opera before 9.26 allows remote attackers to misrepresent web page addresses using "certain characters" that "cause the page address text to be misplaced." | 5.0 |
2008-02-29 | CVE-2008-1082 | Cross-Site Scripting vulnerability in Opera Browser Opera before 9.26 allows remote attackers to "bypass sanitization filters" and conduct cross-site scripting (XSS) attacks via crafted attribute values in an XML document, which are not properly handled during DOM presentation. | 4.3 |
2008-02-29 | CVE-2008-1081 | Code Injection vulnerability in Opera Browser Opera before 9.26 allows user-assisted remote attackers to execute arbitrary script via images that contain custom comments, which are treated as script when the user displays the image properties. | 6.8 |
2008-02-29 | CVE-2008-1080 | Improper Input Validation vulnerability in Opera Browser Opera before 9.26 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename into a file input. | 6.8 |
2007-12-24 | CVE-2007-6522 | Cross-Site Scripting vulnerability in Opera Browser The rich text editing functionality in Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks by using designMode to modify contents of pages in other domains. | 4.3 |
2007-12-24 | CVE-2007-6520 | Cross-Site Scripting vulnerability in Opera Browser Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks via unknown vectors related to plug-ins. | 4.3 |
2007-10-08 | CVE-2007-5276 | Unspecified vulnerability in Opera Browser 9.0 Opera 9 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a session on port 80. network opera | 4.3 |