Vulnerability Name: | CVE-2005-0456 (CCN-18867) | ||||||||
Assigned: | 2005-01-12 | ||||||||
Published: | 2005-01-12 | ||||||||
Updated: | 2022-02-28 | ||||||||
Summary: | Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-0456 Source: MITRE Type: CNA CVE-2005-2273 Source: CCN Type: SA13818 Opera "data:" URI Handler Spoofing Vulnerability Source: SECUNIA Type: Broken Link, Patch 13818 Source: CCN Type: SA15488 Opera Dialog Origin Spoofing Vulnerability Source: CCN Type: GLSA-200502-17 Opera: Multiple vulnerabilities Source: GENTOO Type: Patch, Third Party Advisory, Vendor Advisory GLSA-200502-17 Source: CCN Type: US-CERT VU#882926 Opera may insecurely execute binary data encoded in a URI Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#882926 Source: SUSE Type: Broken Link SUSE-SA:2005:031 Source: CONFIRM Type: Broken Link, Patch, Vendor Advisory http://www.opera.com/linux/changelogs/754u2/ Source: CCN Type: OSVDB ID: 12867 Opera data: URI Handler Application Spoofing Source: CCN Type: OSVDB ID: 79191 Opera Javascript Dialog Origin Spoofing Source: CCN Type: BID-12550 Opera Web Browser Multiple Remote Vulnerabilities Source: CCN Type: BID-18867 AuraCMS Multiple Input Validation Vulnerabilities Source: XF Type: Third Party Advisory, VDB Entry opera-data-dialog-spoofing(18867) Source: XF Type: UNKNOWN opera-data-dialog-spoofing(18867) Source: SUSE Type: SUSE-SA:2005:031 Opera: various problems | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |