Opera Norway AS maintains a broadly deployed web browser and mail client that, despite a focused product portfolio, reaches a substantial installed base across desktop and mobile platforms. Its vulnerability footprint reflects the inherent complexity of browser rendering and script execution: the recurring weakness classes center on input validation and cross-site scripting issues, with a secondary cluster of information-exposure flaws. The vendor's disclosures frequently acquire public exploit code, consistent with the appeal of browsers as targets for proof-of-concept research and tooling development. Defenders should track this vendor's release cycles and prioritize patching across deployed instances, particularly where browser automation or embedded rendering is in use. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opera Norway AS over time
Of all the CVEs published by Opera Norway AS as a CNA, 66.7% affect products that Opera Norway AS develops as a vendor.
Of all the CVEs published that affect products developed by Opera Norway AS, 1.3% are self-published by Opera Norway AS as a CNA.
Signals from CVEs in this vendor scope (325 CVEs).
325 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi | May 21, 2015 | 3.7 | 76 | NO | YES |
CVE-2011-3389MEDIUM The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data b | Sep 6, 2011 | 4.3 | 71 | NO | YES |
CVE-2008-4696MEDIUM Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "option | Oct 23, 2008 | 4.3 | 55 | NO | YES |
CVE-2008-5178HIGH Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680. | Nov 20, 2008 | 9.3 | 53 | NO | YES |
CVE-2011-2628HIGH Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vecto | Jul 1, 2011 | 10.0 | 50 | NO | YES |
CVE-2010-1349HIGH Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow. | Apr 12, 2010 | 10.0 | 49 | NO | YES |
CVE-2011-4684HIGH Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases." | Dec 7, 2011 | 10.0 | 42 | NO | YES |
CVE-2012-6470HIGH Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a m | Jan 2, 2013 | 9.3 | 40 | NO | YES |
CVE-2008-1762HIGH Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern in an HTML CANVAS element, whi | Apr 12, 2008 | 9.3 | 40 | NO | YES |
CVE-2003-1387HIGH Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username. | Dec 31, 2003 | 7.5 | 39 | NO | YES |
Signals from CVEs in this vendor scope (325 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opera Norway AS.
Media articles that mention a CVE ID that affects a product developed by Opera Norway AS — matched by CVE ID, not by vendor name.