Opera Norway AS

First CVE: Dec 18, 2019Active for: 7 years
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
1.5
Avg CVEs / Year
More Avg CVEs / Year than 8% of tracked CNAs
5.6
Avg CVSS Score
Higher Avg CVSS Score than 5% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Opera Norway AS as a CNA, 66.7% affect products that Opera Norway AS develops as a vendor.

66.7%
33.3%
Self-reported: 4Third-party: 2

Of all the CVEs published that affect products developed by Opera Norway AS, 1.3% are self-published by Opera Norway AS as a CNA.

98.7%
Self-published: 4Published by other CNAs: 307

Trends Over Time

The number and severity of CVEs published by Opera Norway AS over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2019
6 years ago
Most Recent CVE
Oct 31, 2025
266 days ago

Top CVEs

All CVEs published by Opera Norway AS as a CNA, regardless of affected vendor or product.

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-service attacks (DoS). GameMaker users who use the network_c
Oct 31, 20257.525NONO
URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this remo
Dec 23, 20206.120NONO
Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypa
Dec 18, 20195.520NONO
Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.a
Jan 11, 20215.318NONO
Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of
Nov 13, 20204.318NONO
Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address o
Feb 21, 20254.715NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA6 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local1 (16.7%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Opera Norway AS as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Opera Norway AS as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs