Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4197

Опубликовано: 27 сент. 2008
Источник: nvd
CVSS3: 8.8
CVSS2: 9.3
EPSS Низкий

Описание

Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*
Версия до 9.52 (исключая)

Одно из

cpe:2.3:o:freebsd:freebsd:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.0508
Низкий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 17 лет назад

Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.

CVSS3: 8.8
github
почти 4 года назад

Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.

EPSS

Процентиль: 90%
0.0508
Низкий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-908