CVE-2003-1420
https://notcve.org/view.php?id=CVE-2003-1420
Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header. • http://www.securityfocus.com/archive/1/313216 http://www.securityfocus.com/bid/6962 https://exchange.xforce.ibmcloud.com/vulnerabilities/11423 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2003-1561
https://notcve.org/view.php?id=CVE-2003-1561
Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data. • http://securityreason.com/securityalert/4004 http://www.securityfocus.com/archive/1/348574 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2003-1397 – Opera 6.0/7.0 - opera.PluginContext Native Method Denial of Service
https://notcve.org/view.php?id=CVE-2003-1397
The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method. • https://www.exploit-db.com/exploits/22240 http://securityreason.com/securityalert/3255 http://www.securityfocus.com/archive/1/311214 http://www.securityfocus.com/bid/6814 https://exchange.xforce.ibmcloud.com/vulnerabilities/11280 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2003-0870 – Opera 7.11/7.20 HREF - Malformed Server Name Heap Corruption
https://notcve.org/view.php?id=CVE-2003-0870
Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name. Desbordamiento de búfer en Opera 7.11 y 7.20 permite a atacantes remotos ejecutar código arbitrario mediante un HREF con un número de largo de caractéres escapados en el nombre del servidor. • https://www.exploit-db.com/exploits/23263 http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0016.html http://www.atstake.com/research/advisories/2003/a102003-1.txt http://www.securityfocus.com/bid/8853 https://exchange.xforce.ibmcloud.com/vulnerabilities/13458 • CWE-787: Out-of-bounds Write •
CVE-2002-2311
https://notcve.org/view.php?id=CVE-2002-2311
Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this issue. • http://online.securityfocus.com/archive/1/283866 http://online.securityfocus.com/archive/1/284068 http://www.iss.net/security_center/static/9653.php http://www.securityfocus.com/bid/5290 • CWE-264: Permissions, Privileges, and Access Controls •