Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opera Norway AS

First CVE: Aug 14, 1998Active for: 28 yearsTotal CVEs: 326
41.8
VTI Score
High

Opera Norway AS maintains a broadly deployed web browser and mail client that, despite a focused product portfolio, reaches a substantial installed base across desktop and mobile platforms. Its vulnerability footprint reflects the inherent complexity of browser rendering and script execution: the recurring weakness classes center on input validation and cross-site scripting issues, with a secondary cluster of information-exposure flaws. The vendor's disclosures frequently acquire public exploit code, consistent with the appeal of browsers as targets for proof-of-concept research and tooling development. Defenders should track this vendor's release cycles and prioritize patching across deployed instances, particularly where browser automation or embedded rendering is in use. Live severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
325
Total CVEs
More Total CVEs than 100% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opera Norway AS over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 1998
27 years ago
Most Recent CVE
Dec 26, 2022
1,307 days ago

Self-Reporting Analysis

Of all the CVEs published by Opera Norway AS as a CNA, 66.7% affect products that Opera Norway AS develops as a vendor.

66.7%
33.3%
Self-reported: 4 (66.7%)
Third-party: 2 (33.3%)

Of all the CVEs published that affect products developed by Opera Norway AS, 1.3% are self-published by Opera Norway AS as a CNA.

98.7%
Self-published: 4 (1.3%)
Other CNAs: 307 (98.7%)

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (325 CVEs).

325 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-4000LOW
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi
May 21, 20153.776NOYES
CVE-2011-3389MEDIUM
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data b
Sep 6, 20114.371NOYES
CVE-2008-4696MEDIUM
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "option
Oct 23, 20084.355NOYES
CVE-2008-5178HIGH
Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680.
Nov 20, 20089.353NOYES
CVE-2011-2628HIGH
Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vecto
Jul 1, 201110.050NOYES
CVE-2010-1349HIGH
Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow.
Apr 12, 201010.049NOYES
CVE-2011-4684HIGH
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."
Dec 7, 201110.042NOYES
CVE-2012-6470HIGH
Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a m
Jan 2, 20139.340NOYES
CVE-2008-1762HIGH
Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern in an HTML CANVAS element, whi
Apr 12, 20089.340NOYES
CVE-2003-1387HIGH
Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.
Dec 31, 20037.539NOYES
View all 325 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products325 CVEs
70%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (0.6%)
Network17 (5.2%)
Unknown306 (94.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (5.2%)
High2 (0.6%)
Unknown306 (94.2%)
User Interaction
None8 (2.5%)
Unknown306 (94.2%)
Required11 (3.4%)
Privileges Required
Low1 (0.3%)
High0 (0.0%)
None18 (5.5%)
Unknown306 (94.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (325 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
0.9% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
36 CVEs
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opera Norway AS.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opera Norway AS — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opera Norway AS's Products

View all 5 CNAs →

Top CWEs