
CVE-2012-6462 – Gentoo Linux Security Advisory 201406-14
https://notcve.org/view.php?id=CVE-2012-6462
02 Jan 2013 — Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request. Opera antes de v12.10 no implementa correctamente la especificición de compartición de recursos de origen cruzado (Cross-Origin Resource Sharing - CORS), la cual permite a atacantes remotos evitar restricciones de acceso a contenidos de páginas a través de una petición hecha a mano. Multiple vulnerabilities ha... • http://www.opera.com/docs/changelogs/unified/1210 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-6470 – Opera Web Browser 12.11 - Crash (PoC)
https://notcve.org/view.php?id=CVE-2012-6470
02 Jan 2013 — Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a malformed image. Opera antes de v12.12 no asigna correctamente la memoria para imágenes GIF, lo que permite a atacantes remotos ejecutar código de su elección o causar una denegación de servicio (sobrescritura de memoria) a través de una imagen con formato incorrecto. Multiple vulnerabilities have been found in Opera, the worst of ... • https://www.exploit-db.com/exploits/23107 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-6466 – Gentoo Linux Security Advisory 201406-14
https://notcve.org/view.php?id=CVE-2012-6466
02 Jan 2013 — Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from process memory by using a crafted image as the fill pattern for a canvas. Opera antes de v12.10 no trata correctamente los datos de tamaño incorrecto en una imagen WebP, lo que permite a atacantes remotos obtener información sensible de la memoria del proceso mediante el uso de una imagen hecha a mano como patrón de relleno para un lienzo. Multiple v... • http://www.opera.com/docs/changelogs/unified/1210 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2012-6461 – Gentoo Linux Security Advisory 201406-14
https://notcve.org/view.php?id=CVE-2012-6461
02 Jan 2013 — The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers to trigger a false indication of successful revocation-status checking by causing a failure of a single checking service. La funcionalidad de validación de certificado X.509 en la implementación de https en Opera antes de v12.10 permite a atacantes remotos provocar una falsa indicación de comprobación exitosa causando un fallo de un servicio de control simple. Multiple vulnerabilities hav... • http://www.opera.com/docs/changelogs/unified/1210 • CWE-20: Improper Input Validation •

CVE-2012-6465 – Gentoo Linux Security Advisory 201406-14
https://notcve.org/view.php?id=CVE-2012-6465
02 Jan 2013 — Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image. Opera antes de v12.10 permite a atacantes remotos ejecutar código de su elección o causar una denegación de servicio (por caída de la aplicación) a través de una imagen SVG mal formada. Multiple vulnerabilities have been found in Opera, the worst of which may allow remote execution of arbitrary code. Versions less than 12.13_p1734 are affected. • http://www.opera.com/docs/changelogs/unified/1210 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2012-6471 – Gentoo Linux Security Advisory 201406-14
https://notcve.org/view.php?id=CVE-2012-6471
02 Jan 2013 — Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests. Opera antes de v12.12 permite a atacantes remotos falsificar el campo de la dirección a través de una alta tasa de peticiones HTTP. Multiple vulnerabilities have been found in Opera, the worst of which may allow remote execution of arbitrary code. Versions less than 12.13_p1734 are affected. • http://www.opera.com/docs/changelogs/unified/1212 •

CVE-2012-6472 – Gentoo Linux Security Advisory 201406-14
https://notcve.org/view.php?id=CVE-2012-6472
02 Jan 2013 — Opera before 12.12 on UNIX uses weak permissions for the profile directory, which allows local users to obtain sensitive information by reading a (1) cache file, (2) password file, or (3) configuration file, or (4) possibly gain privileges by modifying or overwriting a configuration file. Opera antes de v12.12 en UNIX utiliza permisos débiles para el directorio de perfiles, lo que permite a usuarios locales obtener información sensible mediante (1) la lectura de un archivo de caché, (2) el archivo de contra... • http://www.opera.com/docs/changelogs/unified/1212 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-6463 – Gentoo Linux Security Advisory 201406-14
https://notcve.org/view.php?id=CVE-2012-6463
02 Jan 2013 — Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an unspecified sequence of loading of documents and loading of data: URLs. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en Opera antes de v12.10 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados que involucran una secuencia de carga de documentos y carga de URLs del tipo 'data:' .... • http://www.opera.com/docs/changelogs/unified/1210 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2010-5227 – Opera 10.61 - 'dwmapi.dll' DLL Hijacking
https://notcve.org/view.php?id=CVE-2010-5227
07 Sep 2012 — Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .htm, .mht, .mhtml, .xht, .xhtm, or .xhtl file. NOTE: some of these details are obtained from third party information. Vulnerabilidad de ruta de búsqueda no confiable en Opera anterior a v10.62 permite a usuarios locales obtener privilegios a través de un archivo dwmapi.dll caballo de troya en el di... • https://www.exploit-db.com/exploits/14732 •

CVE-2012-4010 – Gentoo Linux Security Advisory 201209-11
https://notcve.org/view.php?id=CVE-2012-4010
30 Aug 2012 — Opera before 11.60 allows remote attackers to spoof the address bar via unspecified homograph characters, a different vulnerability than CVE-2010-2660. Opera anterior a v11.60 permite a atacantes remotos suplantar la barra de direcciones a través de caracteres homógrafos no especificados, una vulnerabilidad diferente a CVE-2010-2660. Multiple vulnerabilities have been found in Opera, the worst of which may allow remote execution of arbitrary code. Versions less than 12.01.1532 are affected. • http://jvn.jp/en/jp/JVN69880570/index.html •