Known Vulnerabilities for products from Opera
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Opera".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-23253 | Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a... | 5.3 - MEDIUM | 2021-01-11 | 2021-01-20 |
| CVE-2020-6159 | URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scri... | 6.1 - MEDIUM | 2020-12-23 | 2020-12-23 |
| CVE-2020-6157 | Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a maliciou... | 4.3 - MEDIUM | 2020-11-13 | 2020-11-30 |
| CVE-2019-19788 | Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service w... | 5.5 - MEDIUM | 2019-12-18 | 2020-01-07 |
| CVE-2019-18624 | Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka R... | 9.8 - CRITICAL | 2019-10-29 | 2023-11-07 |
| CVE-2019-13607 | The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigation to... | 6.1 - MEDIUM | 2019-07-18 | 2019-08-01 |
| CVE-2019-12278 | Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left ord... | 4.3 - MEDIUM | 2020-03-12 | 2020-08-24 |
| CVE-2018-18913 | Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive comp... | 7.8 - HIGH | 2019-03-21 | 2019-09-27 |
| CVE-2018-16135 | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2022-12-26 | 2023-01-05 |
| CVE-2018-6608 | In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information ... | 4.3 - MEDIUM | 2018-03-28 | 2018-04-23 |
| CVE-2016-7153 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, wh... | 5.3 - MEDIUM | 2016-09-06 | 2017-02-19 |
| CVE-2016-7152 | The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, whi... | 5.3 - MEDIUM | 2016-09-06 | 2017-02-19 |
| CVE-2016-6908 | Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 f... | 6.1 - MEDIUM | 2017-01-26 | 2017-01-27 |
| CVE-2016-5101 | Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitra... | 8.8 - HIGH | 2016-06-29 | 2016-11-28 |
| CVE-2016-4075 | Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to t... | 6.1 - MEDIUM | 2017-04-21 | 2022-04-06 |
| CVE-2015-8960 | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for Cli... | 8.1 - HIGH | 2016-09-21 | 2023-01-30 |
| CVE-2015-4000 | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly... | 3.7 - LOW | 2015-05-21 | 2023-02-09 |
| CVE-2014-1870 | Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-d... | 4.3 - MEDIUM | 2014-02-06 | 2014-02-07 |
| CVE-2014-0815 | The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interactio... | 4.3 - MEDIUM | 2014-02-06 | 2017-08-29 |
| CVE-2013-4705 | Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows remote attackers to inject arbitrary web script or HTML... | 4.3 - MEDIUM | 2013-09-13 | 2013-09-13 |
Known software with vulnerabilities from Opera
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Opera | Brew Browser | 6.0 |
| Application | Opera | Mini | 2.0.4719 |
| Application | Opera | Opera | - |
| Application | Opera | Opera Browser | 1.00 |
| Application | Opera | Opera Mail | - |
| Application | Opera | Opera Mini | 7.4 |
| Application | Opera | Opera Mobile | 12.0 |
| Application | Opera | Opera Touch | 1.9.0 |