Opera Software's vulnerability profile centers on its widely used web browser, a client application deployed across diverse end-user systems and platforms. The vendor's disclosures cluster around browser-oriented weakness classes including cross-site scripting, memory-safety issues within the rendering engine, and input-validation flaws—defects that are characteristic of large-scale web browser development. Public exploit code frequently accompanies vulnerabilities in this product class; current severity and exploitation data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opera Software over time
Signals from CVEs in this vendor scope (325 CVEs).
325 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi | May 21, 2015 | 3.7 | 76 | NO | YES |
CVE-2011-3389MEDIUM The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data b | Sep 6, 2011 | 4.3 | 71 | NO | YES |
CVE-2008-4696MEDIUM Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "option | Oct 23, 2008 | 4.3 | 55 | NO | YES |
CVE-2008-5178HIGH Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680. | Nov 20, 2008 | 9.3 | 53 | NO | YES |
CVE-2011-2628HIGH Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vecto | Jul 1, 2011 | 10.0 | 50 | NO | YES |
CVE-2010-1349HIGH Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow. | Apr 12, 2010 | 10.0 | 49 | NO | YES |
CVE-2011-4684HIGH Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases." | Dec 7, 2011 | 10.0 | 42 | NO | YES |
CVE-2012-6470HIGH Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a m | Jan 2, 2013 | 9.3 | 40 | NO | YES |
CVE-2008-1762HIGH Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern in an HTML CANVAS element, whi | Apr 12, 2008 | 9.3 | 40 | NO | YES |
CVE-2003-1387HIGH Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username. | Dec 31, 2003 | 7.5 | 39 | NO | YES |
Signals from CVEs in this vendor scope (325 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opera Software.
Media articles that mention a CVE ID that affects a product developed by Opera Software — matched by CVE ID, not by vendor name.