![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-4046
https://notcve.org/view.php?id=CVE-2010-4046
21 Oct 2010 — Opera before 10.63 does not properly verify the origin of video content, which allows remote attackers to obtain sensitive information by using a video stream as HTML5 canvas content. Opera anterior a v10.63 no verifica adecuadamente el origen del contenido de video, lo que permite a atacantes remotos obtener información sensible usando flujo de video como contenido canvas HTML5 • http://secunia.com/advisories/41740 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-2576
https://notcve.org/view.php?id=CVE-2010-2576
16 Aug 2010 — Opera before 10.61 does not properly suppress clicks on download dialogs that became visible after a recent tab change, which allows remote attackers to conduct clickjacking attacks, and consequently execute arbitrary code, via vectors involving (1) closing a tab or (2) hiding a tab, a related issue to CVE-2005-2407. Opera en versiones anteriores a la v10.61 no suprime apropiadamente clicks y ventanas de diálogo de descarga que se hacen visibles después de un cambio de pestaña reciente, lo que permite a ata... • http://secunia.com/secunia_research/2010-110 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-3021
https://notcve.org/view.php?id=CVE-2010-3021
16 Aug 2010 — Unspecified vulnerability in Opera before 10.61 allows remote attackers to cause a denial of service (CPU consumption and application hang) via an animated PNG image. Vulnerabilidad sin especificar en Opera en versiones anteriores a la v10.61 permite a atacantes remotos provocar una denegación de servicio (consumo de la CPU y caída de la aplicación) a través de una imagen PNG animada. • http://www.opera.com/docs/changelogs/mac/1061 • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-3020
https://notcve.org/view.php?id=CVE-2010-3020
16 Aug 2010 — The news-feed preview feature in Opera before 10.61 does not properly remove scripts, which allows remote attackers to force subscriptions to arbitrary feeds via crafted content. La funcionalidad previsualización de feeds en Opera en versiones anteriores a la v10.61 no eliminan apropiadamente scripts, lo que permite a atacantes remotos forzar subscripciones a feeds de su elección a través de contenido modificado. • http://www.opera.com/docs/changelogs/mac/1061 • CWE-264: Permissions, Privileges, and Access Controls •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-3019
https://notcve.org/view.php?id=CVE-2010-3019
16 Aug 2010 — Heap-based buffer overflow in Opera before 10.61 allows remote attackers to execute arbitrary code or cause a denial of service (application crash or hang) via vectors related to HTML5 canvas painting operations that occur during the application of transformations. Desbordamiento de buffer basado en memoria dinámica en Opera en versiones anteriores a la v10.61 permite a atacantes remotos ejecutar comandos de su elección o provocar una denegación de servicio (caída o cuelgue de la aplicación) a través de vec... • http://www.opera.com/docs/changelogs/mac/1061 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-2661
https://notcve.org/view.php?id=CVE-2010-2661
07 Jul 2010 — Opera before 10.54 on Windows and Mac OS X, and before 10.60 on UNIX platforms, does not properly restrict access to the full pathname of a file selected for upload, which allows remote attackers to obtain potentially sensitive information via unspecified DOM manipulations. Opera anterior a v10.54 en Windows y Mac OS X, y anterior a v10.60 en las plataformas UNIX, no restringe adecuadamente el acceso a la ruta completa de un archivo seleccionado para la carga, lo cual permite a atacantes remotos obtener inf... • http://secunia.com/advisories/40250 • CWE-264: Permissions, Privileges, and Access Controls •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-2662
https://notcve.org/view.php?id=CVE-2010-2662
07 Jul 2010 — Opera before 10.60 allows remote attackers to bypass the popup blocker via a javascript: URL and a "fake click." Opera anterior a v10.60 permite a atacantes remotos eludir el bloqueador de ventanas emergentes a través de una URL javascript y un "clic falso". • http://www.opera.com/docs/changelogs/mac/1060 • CWE-264: Permissions, Privileges, and Access Controls •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-2663
https://notcve.org/view.php?id=CVE-2010-2663
07 Jul 2010 — Opera before 10.60 allows remote attackers to cause a denial of service (application hang) via an ended event handler that changes the SRC attribute of an AUDIO element. Opera anterior a v10.60 permite a atacantes remotos provocar una denegación de servicio (cuelgue de aplicación) a través de un controlador de eventos que cambia el atributo SRC de un elemento AUDIO. • http://www.opera.com/docs/changelogs/mac/1060 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-2665
https://notcve.org/view.php?id=CVE-2010-2665
07 Jul 2010 — Cross-site scripting (XSS) vulnerability in Opera before 10.54 on Windows and Mac OS X, and before 10.11 on UNIX platforms, allows remote attackers to inject arbitrary web script or HTML via a data: URI, related to incorrect detection of the "opening site." Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Opera anterior a v10.54 en Windows y Mac OS X, y anterior a v10.11 en las plataformas UNIX, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través ... • http://secunia.com/advisories/40250 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2010-2659
https://notcve.org/view.php?id=CVE-2010-2659
07 Jul 2010 — Opera before 10.50 on Windows, before 10.52 on Mac OS X, and before 10.60 on UNIX platforms makes widget properties accessible to third-party domains, which allows remote attackers to obtain potentially sensitive information via a crafted web site. Opera anterior a v10.50 en Windows, anterior a v10.52 en Mac OS X, y anterior a v10.60 en plataformas UNIX hace accesibles las propiedades de los widges a dominios de terceros, lo cual permite a los atacantes remotos obtener información potencialmente sensible a ... • http://www.opera.com/docs/changelogs/mac/1052 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •