📦

opera_browser

Vendor: opera

Actively Exploited 0 CISA KEV List
PoC / Exploits 26 Code Available
Total RCEs 30 Remote Access
Total CVEs 2033 Total Indexed
Avg. EPSS 3.16% Exploit Prob.
Latest CVE CVE-2018-18913 Mar 21

Security Vulnerability Index

Page 5 / 204
5.0 CVSS

Opera before 12.00 Beta allows remote attackers to cause a denial of service (application hang) via an absolutely positioned wrap=off TEXTAREA element located next to an "overflow: auto" block element.

EPSS: 0.47%
5.0 CVSS

Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via a web page that contains invalid character encodings.

EPSS: 0.44%
4.3 CVSS

Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload, as demonstrated by a "multiple origin camera test" page.

EPSS: 0.41%
10.0 CVSS

Opera before 11.64 does not properly allocate memory for URL strings, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted string.

EPSS: 7.30%
4.3 CVSS

Opera before 11.65 does not ensure that the address field corresponds to the displayed web page during blocked navigation, which makes it easier for remote attackers to conduct spoofing attacks by detecting and preventing attempts to load a different web page.

EPSS: 0.48%
10.0 CVSS

Unspecified vulnerability in Opera before 12.00 on Mac OS X has unknown impact and attack vectors, related to a "moderate severity issue."

EPSS: 0.33%
2.6 CVSS

Opera before 11.65 does not ensure that the address field corresponds to the displayed web page during unusually timed changes to this field, which makes it easier for user-assisted remote attackers to conduct spoofing attacks via vectors involving navigation, reloads, and redirects.

EPSS: 0.34%
5.0 CVSS

Opera before 11.65 does not properly restrict the reading of JSON strings, which allows remote attackers to perform cross-domain loading of JSON resources and consequently obtain sensitive information via a crafted web site.

EPSS: 0.38%
9.3 CVSS

Opera before 11.65 does not properly restrict the opening of a pop-up window in response to the first click of a double-click action, which makes it easier for user-assisted remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary code via a crafted web site.

EPSS: 2.35%
7.6 CVSS

Opera before 11.65 does not ensure that keyboard sequences are associated with a visible window, which makes it easier for user-assisted remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary code via a crafted web site, related to a "hidden keyboard navigation" issue.

EPSS: 4.59%