
CVE-2010-4043
https://notcve.org/view.php?id=CVE-2010-4043
21 Oct 2010 — Opera before 10.63 does not prevent interpretation of a cross-origin document as a CSS stylesheet when the document lacks a CSS token sequence, which allows remote attackers to obtain sensitive information via a crafted document. Opera anterior a v10.63 no previene de una interpretación de documento cross-origin como las hojas de estilo CSS cuando el documento carece de una secuencia de token CSS, que permite a atacantes remotos obtener información confidencial a través de documentos manipulados. • http://secunia.com/advisories/41740 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2010-3019 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-3019
16 Aug 2010 — Heap-based buffer overflow in Opera before 10.61 allows remote attackers to execute arbitrary code or cause a denial of service (application crash or hang) via vectors related to HTML5 canvas painting operations that occur during the application of transformations. Desbordamiento de buffer basado en memoria dinámica en Opera en versiones anteriores a la v10.61 permite a atacantes remotos ejecutar comandos de su elección o provocar una denegación de servicio (caída o cuelgue de la aplicación) a través de vec... • http://www.opera.com/docs/changelogs/mac/1061 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2010-3020 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-3020
16 Aug 2010 — The news-feed preview feature in Opera before 10.61 does not properly remove scripts, which allows remote attackers to force subscriptions to arbitrary feeds via crafted content. La funcionalidad previsualización de feeds en Opera en versiones anteriores a la v10.61 no eliminan apropiadamente scripts, lo que permite a atacantes remotos forzar subscripciones a feeds de su elección a través de contenido modificado. Multiple vulnerabilities have been found in Opera, the worst of which allow for the execution o... • http://www.opera.com/docs/changelogs/mac/1061 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2010-3021 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-3021
16 Aug 2010 — Unspecified vulnerability in Opera before 10.61 allows remote attackers to cause a denial of service (CPU consumption and application hang) via an animated PNG image. Vulnerabilidad sin especificar en Opera en versiones anteriores a la v10.61 permite a atacantes remotos provocar una denegación de servicio (consumo de la CPU y caída de la aplicación) a través de una imagen PNG animada. Multiple vulnerabilities have been found in Opera, the worst of which allow for the execution of arbitrary code. Versions le... • http://www.opera.com/docs/changelogs/mac/1061 • CWE-399: Resource Management Errors •

CVE-2010-2576 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-2576
13 Aug 2010 — Opera before 10.61 does not properly suppress clicks on download dialogs that became visible after a recent tab change, which allows remote attackers to conduct clickjacking attacks, and consequently execute arbitrary code, via vectors involving (1) closing a tab or (2) hiding a tab, a related issue to CVE-2005-2407. Opera en versiones anteriores a la v10.61 no suprime apropiadamente clicks y ventanas de diálogo de descarga que se hacen visibles después de un cambio de pestaña reciente, lo que permite a ata... • http://secunia.com/secunia_research/2010-110 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2010-2661 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-2661
07 Jul 2010 — Opera before 10.54 on Windows and Mac OS X, and before 10.60 on UNIX platforms, does not properly restrict access to the full pathname of a file selected for upload, which allows remote attackers to obtain potentially sensitive information via unspecified DOM manipulations. Opera anterior a v10.54 en Windows y Mac OS X, y anterior a v10.60 en las plataformas UNIX, no restringe adecuadamente el acceso a la ruta completa de un archivo seleccionado para la carga, lo cual permite a atacantes remotos obtener inf... • http://secunia.com/advisories/40250 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2010-2659 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-2659
07 Jul 2010 — Opera before 10.50 on Windows, before 10.52 on Mac OS X, and before 10.60 on UNIX platforms makes widget properties accessible to third-party domains, which allows remote attackers to obtain potentially sensitive information via a crafted web site. Opera anterior a v10.50 en Windows, anterior a v10.52 en Mac OS X, y anterior a v10.60 en plataformas UNIX hace accesibles las propiedades de los widges a dominios de terceros, lo cual permite a los atacantes remotos obtener información potencialmente sensible a ... • http://www.opera.com/docs/changelogs/mac/1052 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2010-2665 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-2665
07 Jul 2010 — Cross-site scripting (XSS) vulnerability in Opera before 10.54 on Windows and Mac OS X, and before 10.11 on UNIX platforms, allows remote attackers to inject arbitrary web script or HTML via a data: URI, related to incorrect detection of the "opening site." Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Opera anterior a v10.54 en Windows y Mac OS X, y anterior a v10.11 en las plataformas UNIX, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través ... • http://secunia.com/advisories/40250 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2010-2658 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-2658
07 Jul 2010 — Opera before 10.60 does not properly restrict certain interaction between plug-ins, file inputs, and the clipboard, which allows user-assisted remote attackers to trigger the uploading of arbitrary files via a crafted web site. Opera anterior a v10.60 no limita propiamente cierta interacción entre los plug-ins, entradas de ficheros, y el porta papeles, lo cual permite a atacantes remotos ayudados por el usuario activar la subida de archivos arbitrarios a través de un sitio web manipulado. Multiple vulnerabi... • http://secunia.com/advisories/40375 • CWE-20: Improper Input Validation •

CVE-2010-2662 – Gentoo Linux Security Advisory 201206-03
https://notcve.org/view.php?id=CVE-2010-2662
07 Jul 2010 — Opera before 10.60 allows remote attackers to bypass the popup blocker via a javascript: URL and a "fake click." Opera anterior a v10.60 permite a atacantes remotos eludir el bloqueador de ventanas emergentes a través de una URL javascript y un "clic falso". Multiple vulnerabilities have been found in Opera, the worst of which allow for the execution of arbitrary code. Versions less than 12.00.1467 are affected. • http://www.opera.com/docs/changelogs/mac/1060 • CWE-264: Permissions, Privileges, and Access Controls •