Описание
Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.
Ссылки
- Broken LinkPatch
- PatchThird Party AdvisoryVendor Advisory
- Third Party AdvisoryUS Government Resource
- Broken Link
- Broken LinkPatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Broken LinkPatch
- PatchThird Party AdvisoryVendor Advisory
- Third Party AdvisoryUS Government Resource
- Broken Link
- Broken LinkPatchVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 7.54 (включая)
cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06168
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
github
почти 4 года назад
Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.
EPSS
Процентиль: 91%
0.06168
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo