Описание
Opera before 11.65 does not ensure that the address field corresponds to the displayed web page during blocked navigation, which makes it easier for remote attackers to conduct spoofing attacks by detecting and preventing attempts to load a different web page.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.64 (включая)
Одно из
cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta3:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta4:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta5:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta6:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta7:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta8:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.10:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.11:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.12:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:beta3:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:tp1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:tp2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:tp3:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.1:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.1:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.03:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.04:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.05:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.06:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.11:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.12:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.0:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.0:beta1_v2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.03:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.10:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.10:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.11:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.11:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.20:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.20:beta7:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.21:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.22:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.50:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.50:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.51:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.52:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.53:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.54:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.54:update1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.54:update2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.50:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.51:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.52:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.53:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.54:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.0:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.10:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.20:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.20:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.21:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.22:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.23:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.24:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.25:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.26:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.27:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.50:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.50:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.50:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.51:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.52:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.60:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.60:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.61:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.62:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.63:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.64:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.00:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.00:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.00:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.00:beta3:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.10:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.10:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.11:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.50:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.50:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.50:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.51:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.52:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.52:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.52:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.53:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.53:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.54:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.60:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.60:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.61:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.62:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:10.63:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.00:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.00:beta:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.10:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.10:beta:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.11:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.50:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.50:beta:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.51:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.52:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.60:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.60:beta:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.61:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:11.62:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00722
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 3 лет назад
Opera before 11.65 does not ensure that the address field corresponds to the displayed web page during blocked navigation, which makes it easier for remote attackers to conduct spoofing attacks by detecting and preventing attempts to load a different web page.
EPSS
Процентиль: 72%
0.00722
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-264