Vulnerabilities > Opera > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-09-16 | CVE-2004-0872 | Incorrect Resource Transfer Between Spheres vulnerability in Opera Browser 7.51 Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection." | 5.0 |
2004-08-06 | CVE-2004-0537 | Unspecified vulnerability in Opera Browser Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces. | 5.0 |
2003-12-31 | CVE-2003-1561 | Information Disclosure vulnerability in Opera Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data. network opera | 4.3 |
2003-12-31 | CVE-2003-1420 | Cross-site Scripting vulnerability in Opera Browser Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header. | 4.3 |
2003-12-31 | CVE-2003-1397 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Opera Browser 6.05/7.0/7.01 The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method. | 4.3 |
2003-12-31 | CVE-2003-1396 | Out-of-bounds Write vulnerability in Opera Browser Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension. | 6.8 |