
CVE-2011-0682 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2011-0682
31 Jan 2011 — Integer truncation error in opera.dll in Opera before 11.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML form with a select element that contains a large number of children. Un error de truncamiento de enteros en la biblioteca opera.dll en Opera anterior a versión 11.01, permite a los atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) por medio de un formulario HTML con un elemento select ... • http://osvdb.org/70728 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2011-0685 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2011-0685
31 Jan 2011 — The Delete Private Data feature in Opera before 11.01 does not properly implement the "Clear all email account passwords" option, which might allow physically proximate attackers to access an e-mail account via an unattended workstation. La característica de borrado de datos privados en Opera anterior a v11.01 no implementa adecuadamente la opción "Borrar todas las contraseñas de cuenta de correo electrónico", que podría permitir a atacantes físicamente próximos acceder a una cuenta de correo electrónico a ... • http://osvdb.org/70731 • CWE-20: Improper Input Validation •

CVE-2011-0683 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2011-0683
31 Jan 2011 — Opera before 11.01 does not properly restrict the use of opera: URLs, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. Opera anterior v.11.01 no restringe correctamente el uso de Opera: URLs, que hace más fácil para los atacantes remotos conducir un ataque de "clickjacking" a través de un sitio web manipulado. Multiple vulnerabilities have been found in Opera, the worst of which allow for the execution of arbitrary code. Versions less than 12.00.1467 are aff... • http://osvdb.org/70729 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2011-0450
https://notcve.org/view.php?id=CVE-2011-0450
31 Jan 2011 — The downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers to execute arbitrary code via a crafted web site that hosts an executable file. El administrador de descargas en Opera anterior v11.01 sobre Windows no determina adecuadamente la ruta de la aplicación del visualizador del sistema de archivos, lo que permite a atacantes remotos asistidos por el usuario ejecutar código de su elección... • http://jvn.jp/en/jp/JVN33880169/index.html •

CVE-2010-4582 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-4582
22 Dec 2010 — Opera before 11.00 does not properly handle security policies during updates to extensions, which might allow remote attackers to bypass intended access restrictions via unspecified vectors. Opera anterior v11.00 no maneja adecuadamente políticas de seguridad durante la actualización de extensiones, lo que puede permitir a atacantes remotos superar las restricciones de acceso establecidas a través de vectores no especificados. Multiple vulnerabilities have been found in Opera, the worst of which allow for t... • http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2010-4579 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-4579
22 Dec 2010 — Opera before 11.00 does not properly constrain dialogs to appear on top of rendered documents, which makes it easier for remote attackers to trick users into interacting with a crafted web site that spoofs the (1) security information dialog or (2) download dialog. Opera anterior v11.00 no limita adecuadamente los diálogos que aparecen en los documentos renderizados, lo que hace que sea posible para atacantes remotos engañar a los usuarios interactuando con un sitio web manipulado que falsifica el (1) diálo... • http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html •

CVE-2010-4583 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-4583
22 Dec 2010 — Opera before 11.00, when Opera Turbo is enabled, does not display a page's security indication, which makes it easier for remote attackers to spoof trusted content via a crafted web site. Opera anterior a v11.00, cuando se habilita Opera Turbo, no muestra la indicación de página segura, lo cual hace más facil a los atacantes remotos suplantar contenidos de confianza a través de sitios web manipulados. Multiple vulnerabilities have been found in Opera, the worst of which allow for the execution of arbitrary ... • http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html •

CVE-2010-4581 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-4581
22 Dec 2010 — Unspecified vulnerability in Opera before 11.00 has unknown impact and attack vectors, related to "a high severity issue." Vulnerabilidad no especificada en Opera anterior a v11.00 tiene un impacto y vectores de ataque desconocidos, relacionado con una "incidencia de alta gravedad". Multiple vulnerabilities have been found in Opera, the worst of which allow for the execution of arbitrary code. Versions less than 12.00.1467 are affected. • http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html •

CVE-2010-4580 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-4580
22 Dec 2010 — Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive information via an input field that has the same name as an input field on a previously visited web site. Opera, en versiones anteriores a la 11.00, no limpia los campos de formulario WAP WML después de navegar manualmente a un nuevo sitio web, lo que permite a atacantes remotos obtener información sensible mediante un campo de entrada que tenga el mismo nombre q... • http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2010-4585 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-4585
22 Dec 2010 — Unspecified vulnerability in the auto-update functionality in Opera before 11.00 allows remote attackers to cause a denial of service (application crash) by triggering an Opera Unite update. Vulnerabilidad sin especificar en la funcionalidad auto-update en Opera anterior a v11.00 permite a los atacantes remotos causar una denegación de servicio (fallo de la aplicación) al lanzar una actualización Opera Unite. Multiple vulnerabilities have been found in Opera, the worst of which allow for the execution of ar... • http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html •