Known Vulnerabilities for products from Opera
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Opera".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-23253 json | Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a... | 5.3 - MEDIUM | 2021-01-11 | 2021-01-20 |
| CVE-2020-6159 json | URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scri... | 6.1 - MEDIUM | 2020-12-23 | 2020-12-23 |
| CVE-2020-6157 json | Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a maliciou... | 4.3 - MEDIUM | 2020-11-13 | 2020-11-30 |
| CVE-2019-19788 json | Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service w... | 5.5 - MEDIUM | 2019-12-18 | 2020-01-07 |
| CVE-2019-18624 json | Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka R... | 9.8 - CRITICAL | 2019-10-29 | 2023-11-07 |
| CVE-2019-13607 json | The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigation to... | 6.1 - MEDIUM | 2019-07-18 | 2019-08-01 |
| CVE-2019-12278 json | Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left ord... | 4.3 - MEDIUM | 2020-03-12 | 2020-08-24 |
| CVE-2018-18913 json | Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive comp... | 7.8 - HIGH | 2019-03-21 | 2019-09-27 |
| CVE-2018-16135 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2022-12-26 | 2023-01-05 |
| CVE-2018-6608 json | In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information ... | 4.3 - MEDIUM | 2018-03-28 | 2018-04-23 |
| CVE-2016-7153 json | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, wh... | 5.3 - MEDIUM | 2016-09-06 | 2017-02-19 |
| CVE-2016-7152 json | The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, whi... | 5.3 - MEDIUM | 2016-09-06 | 2017-02-19 |
| CVE-2016-6908 json | Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 f... | 6.1 - MEDIUM | 2017-01-26 | 2017-01-27 |
| CVE-2016-5101 json | Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitra... | 8.8 - HIGH | 2016-06-29 | 2016-11-28 |
| CVE-2016-4075 json | Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to t... | 6.1 - MEDIUM | 2017-04-21 | 2022-04-06 |
| CVE-2015-8960 json | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for Cli... | 8.1 - HIGH | 2016-09-21 | 2023-01-30 |
| CVE-2015-4000 json | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly... | 3.7 - LOW | 2015-05-21 | 2023-02-09 |
| CVE-2014-1870 json | Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-d... | 4.3 - MEDIUM | 2014-02-06 | 2014-02-07 |
| CVE-2014-0815 json | The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interactio... | 4.3 - MEDIUM | 2014-02-06 | 2017-08-29 |
| CVE-2013-4705 json | Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows remote attackers to inject arbitrary web script or HTML... | 4.3 - MEDIUM | 2013-09-13 | 2013-09-13 |
Known software with vulnerabilities from Opera
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Opera | Brew Browser | 6.0 |
| Application | Opera | Mini | 16.0.14 |
| Application | Opera | Opera | - |
| Application | Opera | Opera Browser | 1.00 |
| Application | Opera | Opera Mail | - |
| Application | Opera | Opera Mini | 10.0.1884.93721 |
| Application | Opera | Opera Mobile | 12.0 |
| Application | Opera | Opera Touch | 1.10.0 |