📦

opera_browser

Vendor: opera

Actively Exploited 0 CISA KEV List
PoC / Exploits 26 Code Available
Total RCEs 30 Remote Access
Total CVEs 2033 Total Indexed
Avg. EPSS 3.15% Exploit Prob.
Latest CVE CVE-2018-18913 Mar 21

Security Vulnerability Index

Page 11 / 204
5.0 CVSS

The SVG implementation in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via vectors involving a path on which many characters are drawn.

EPSS: 0.54%
5.0 CVSS

The Array.prototype.join method in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via a non-array object that contains initial holes.

EPSS: 0.54%
5.0 CVSS

Unspecified vulnerability in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by progorod.ru.

EPSS: 0.49%
4.3 CVSS

Unspecified vulnerability in the printing functionality in Opera before 11.50 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page.

EPSS: 0.46%
10.0 CVSS

Unspecified vulnerability in Opera before 11.50 has unknown impact and attack vectors, related to a "moderately severe issue."

EPSS: 0.55%
4.3 CVSS

Opera before 11.50 does not properly restrict data: URIs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.

EPSS: 0.51%
4.3 CVSS

Opera before 11.50 allows remote attackers to cause a denial of service (disk consumption) via invalid URLs that trigger creation of error pages.

EPSS: 2.02%
4.3 CVSS

The VEGAOpBitmap::AddLine function in Opera before 10.61 does not properly initialize memory during processing of the SIZE attribute of a SELECT element, which allows remote attackers to trigger an invalid memory write operation, and consequently cause a denial of service (application crash) or possibly execute arbitrary code, via a large integer attribute value.

EPSS: 7.86%
4.3 CVSS

Opera before 11.01 does not properly implement Wireless Application Protocol (WAP) dropdown lists, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted WAP document.

EPSS: 1.57%
5.0 CVSS

Unspecified vulnerability in Opera before 11.01 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by vkontakte.ru.

EPSS: 1.35%