📦

opera_browser

Vendor: opera

Actively Exploited 0 CISA KEV List
PoC / Exploits 26 Code Available
Total RCEs 30 Remote Access
Total CVEs 2033 Total Indexed
Avg. EPSS 3.15% Exploit Prob.
Latest CVE CVE-2018-18913 Mar 21

Security Vulnerability Index

Page 9 / 204
5.0 CVSS

Opera before 11.10 allows remote attackers to hijack (1) searches and (2) customizations via unspecified third party applications.

EPSS: 0.27%
5.0 CVSS

Unspecified vulnerability in Opera before 11.11 allows remote attackers to cause a denial of service (application crash) via vectors involving a Certificate Revocation List (CRL) file, as demonstrated by the multicert-ca-02.crl file.

EPSS: 0.29%
5.0 CVSS

Opera before 11.11 does not properly handle destruction of a Silverlight instance, which allows remote attackers to cause a denial of service (application crash) via a web page, as demonstrated by vod.onet.pl.

EPSS: 0.49%
5.0 CVSS

The Cascading Style Sheets (CSS) implementation in Opera before 11.11 does not properly handle the column-count property, which allows remote attackers to cause a denial of service (infinite repaint loop and application hang) via a web page, as demonstrated by an unspecified Wikipedia page.

EPSS: 0.49%
4.3 CVSS

Opera before 11.11 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload occurring after the opening of a popup of the Easy Sticky Note extension.

EPSS: 0.46%
5.0 CVSS

Unspecified vulnerability in Opera before 11.11 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by www.falk.de.

EPSS: 0.49%
10.0 CVSS
CVE-2011-2628
Exploit Found

Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload.

EPSS: 10.55%
5.0 CVSS

Unspecified vulnerability in the DOM implementation in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by live.com.

EPSS: 0.49%
5.0 CVSS

Opera before 11.50 allows remote attackers to cause a denial of service (application crash) by using "injected script" to set the SRC attribute of an IFRAME element.

EPSS: 0.54%
5.0 CVSS

Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via a SELECT element that contains many OPTION elements.

EPSS: 0.54%