
CVE-2006-6970
https://notcve.org/view.php?id=CVE-2006-6970
07 Feb 2007 — Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name, as demonstrated by the "." and "/" characters, which is not caught by the blacklist filter. Opera 9.10 Final permite a atacantes remotos evitar el mecanismo de Protección de Fraude (Fraud Protection) añadiendo ciertos caracteres al final del nombre de dominio, como lo demostrado mediante los caracteres "." y "/", que no son capturados por los filtros de las listas negra... • http://kaneda.bohater.net/security/20061220-opera_9.10_final_bypass_fraud_protection.php • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2006-6955
https://notcve.org/view.php?id=CVE-2006-6955
29 Jan 2007 — Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723. Opera permite a atacantes remotos provocar una denegación de servicio (cierre de aplicación) mediante una página web que contiene un gran número de etiquetas de marquesina anidadas, un problema relacionado con CVE-2006-2723. • http://archives.neohapsis.com/archives/bugtraq/2006-06/0085.html • CWE-20: Improper Input Validation •

CVE-2002-0270
https://notcve.org/view.php?id=CVE-2002-0270
03 May 2002 — Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks. • http://marc.info/?l=bugtraq&m=101363764421623&w=2 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •