📦

opera_browser

Vendor: opera

Actively Exploited 0 CISA KEV List
PoC / Exploits 26 Code Available
Total RCEs 30 Remote Access
Total CVEs 2033 Total Indexed
Avg. EPSS 3.16% Exploit Prob.
Latest CVE CVE-2018-18913 Mar 21

Security Vulnerability Index

Page 4 / 204
5.0 CVSS

Opera before 11.60 allows remote attackers to spoof the address bar via unspecified homograph characters, a different vulnerability than CVE-2010-2660.

EPSS: 0.27%
4.3 CVSS

Opera before 12.01 allows remote attackers to cause a denial of service (application crash) via a crafted web site, as demonstrated by the Lenovo "Shop now" page.

EPSS: 0.46%
10.0 CVSS

Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue."

EPSS: 0.41%
4.3 CVSS

Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted HTML document.

EPSS: 0.40%
6.8 CVSS

Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog, a different vulnerability than CVE-2012-1924.

EPSS: 0.67%
4.3 CVSS

Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, ignores some characters in HTML documents in unspecified circumstances, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.

EPSS: 0.42%
5.0 CVSS

Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via crafted WebGL content, as demonstrated by a codeflow.org WebGL demo.

EPSS: 0.44%
5.0 CVSS

Opera before 12.00 Beta allows remote attackers to cause a denial of service (memory consumption or application hang) via an IFRAME element that uses the src="#" syntax to embed a parent document.

EPSS: 0.47%
4.3 CVSS

Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (application hang) via JavaScript code that changes a form before submission.

EPSS: 0.44%
5.0 CVSS

Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via crafted characters in domain names, as demonstrated by "IDNA2008 tests."

EPSS: 0.47%