Category Archives: advisory

Startup crash can allow execution of arbitrary code – Opera Security Advisories

Severity Extremely Severe Problem Description  When Opera is registered as a handler for a given protocol, it can be started by external applications. In some cases, being started in this way can cause Opera to crash. To inject code, additional techniques will have to be employed.  Affected versions This vulnerability affects Opera for Microsoft Windows.…

Registering Opera as a protocol handler can allow it to be used to execute arbitrary code – Opera Security Advisories

Severity Extremely Severe Problem Description  When an application attempts to access a URL that uses a protocol that it does not understand, it may choose to pass the URL to a registered handler for that protocol. If that registered handler is Opera, it will be started, passing the URL to open. Some external applications do not…

Resized canvas patterns can cause Opera to execute arbitrary code – Opera Security Advisories

Severity  Moderately Severe  Problem Description  HTML CANVAS elements can use scaled images as patterns. With suitable scaling manipulation of the image, a script can cause Opera to crash. This crash can sometimes cause memory corruption. To inject code, additional techniques will have to be employed.  Opera’s Response  Opera Software has released Opera 9.27 with a…

Representation of DOM attribute values could allow cross-site scripting – Opera Security Advisories

Severity Moderately Severe Problem Description When XML is imported into a document, its attribute values are not correctly presented to the DOM. This can allow their values to bypass sanitization filters. If these values are used as document content, they may in some cases allow scripts to be inserted. Opera’s Response Opera Software has released…

Image properties can be used to execute scripts – Opera Security Advisories

Severity Highly Severe Problem Description Image properties can contain custom comments. When displaying the image properties, Opera can be tricked into treating the comments as script. This can cause the script to be run in the wrong security context. Opera’s Response Opera Software has released Opera 9.26, where this issue has been fixed. Credits Thanks…