Vulnerability Name: | CVE-2005-3041 (CCN-24099) | ||||||||
Assigned: | 2005-09-20 | ||||||||
Published: | 2005-09-20 | ||||||||
Updated: | 2022-02-28 | ||||||||
Summary: | Unspecified "drag-and-drop vulnerability" in Opera Web Browser before 8.50 on Windows allows "unintentional file uploads." | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-3007 Source: MITRE Type: CNA CVE-2005-3041 Source: MITRE Type: CNA CVE-2005-3059 Source: MITRE Type: CNA CVE-2005-3946 Source: CCN Type: SA16645 Opera Mail Client Attachment Spoofing and Script Insertion Source: CCN Type: Opera Website Opera 8.50 for Windows Changelog Source: CONFIRM Type: Broken Link, Patch http://www.opera.com/docs/changelogs/windows/850/ Source: CCN Type: OSVDB ID: 19509 Opera Mail Client Crafted Content-Type File Extension Spoofing Source: CCN Type: OSVDB ID: 19739 Opera HTTPS must-revalidate Cache Directive Unspecified Issue Source: CCN Type: OSVDB ID: 19740 Opera Cookie Comment Encoding Unspecified Issue Source: CCN Type: OSVDB ID: 20003 Opera Drag and Drop Unspecified File Upload Source: CCN Type: OSVDB ID: 21494 Opera JNI com.opera.JSObject Class Crafted Applet DoS Source: CCN Type: BID-14880 Opera Web Browser Mail Client Multiple Vulnerabilities Source: BID Type: Broken Link, Patch, Third Party Advisory, VDB Entry 14884 Source: CCN Type: BID-14884 Opera Web Browser Unspecified Drag And Drop File Upload Vulnerability Source: CCN Type: BID-15647 RETIRED: Apple Mac OS X Security Update 2005-009 Multiple Vulnerabilities Source: VUPEN Type: Broken Link ADV-2005-1789 Source: XF Type: UNKNOWN opera-mustrevalidate-cookie(24099) Source: SUSE Type: SUSE-SA:2005:057 opera: remote code execution | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |