Vulnerability Name: | CVE-2006-4819 (CCN-29632) | ||||||||
Assigned: | 2006-10-17 | ||||||||
Published: | 2006-10-17 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Heap-based buffer overflow in Opera 9.0 and 9.01 allows remote attackers to execute arbitrary code via a long URL in a tag (long link address). | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 3.8 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-4819 Source: IDEFENSE Type: Patch, Vendor Advisory 20061017 Opera Software Opera Web Browser URL Parsing Heap Overflow Vulnerability Source: CCN Type: SA22218 Opera Web Browser URL Handling Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 22218 Source: SECUNIA Type: UNKNOWN 22509 Source: CCN Type: SECTRACK ID: 1017080 Opera Large Link Address Heap Overflow Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1017080 Source: CCN Type: US-CERT VU#484380 Opera Web Browser fails to properly process overly long URLs Source: CERT-VN Type: US Government Resource VU#484380 Source: SUSE Type: UNKNOWN SUSE-SA:2006:061 Source: CCN Type: Opera Web site Download Opera Web Browser Source: CONFIRM Type: Patch, Vendor Advisory http://www.opera.com/support/search/supsearch.dml?index=848 Source: CCN Type: OSVDB ID: 29785 Opera Tag URL Handling Overflow Source: BID Type: UNKNOWN 20591 Source: CCN Type: BID-20591 Opera Web Browser URI Tag Parsing Heap Buffer Overflow Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-4066 Source: XF Type: UNKNOWN opera-tag-url-bo(29632) Source: XF Type: UNKNOWN opera-tag-url-bo(29632) Source: CCN Type: iDEFENSE ADVISORY: 10.17.06 Opera Software Opera Web Browser URL Parsing Heap Overflow Vulnerability Source: SUSE Type: SUSE-SA:2006:061 opera security problems | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |