Vulnerability Name: | CVE-2007-0126 (CCN-31305) | ||||||||
Assigned: | 2007-01-05 | ||||||||
Published: | 2007-01-05 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-0126 Source: IDEFENSE Type: Vendor Advisory 20070105 Opera Software Opera Web Browser JPG Image DHT Marker Heap Corruption Vulnerability Source: SUSE Type: UNKNOWN SUSE-SA:2007:009 Source: OSVDB Type: UNKNOWN 31574 Source: CCN Type: SA23613 Opera Browser Two Vulnerabilities Source: SECUNIA Type: Vendor Advisory 23613 Source: SECUNIA Type: UNKNOWN 23739 Source: SECUNIA Type: UNKNOWN 23771 Source: CCN Type: SECTRACK ID: 1017473 Opera JPEG DHT Marker Buffer Overflow and createSVGTransformFromMatrix Request Validation Flaw Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1017473 Source: CCN Type: GLSA-200701-08 Opera: Two remote code execution vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-200701-08 Source: CCN Type: Opera Web site Download Opera Web Browser Source: CONFIRM Type: Patch, Vendor Advisory http://www.opera.com/support/search/supsearch.dml?index=852 Source: CCN Type: OSVDB ID: 31574 Opera JPEG DHT Invalid Index Byte Overflow Source: VUPEN Type: UNKNOWN ADV-2007-0060 Source: XF Type: UNKNOWN opera-jpeg-dht-bo(31305) Source: XF Type: UNKNOWN opera-jpeg-dht-bo(31305) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 01.05.07 Opera Software Opera Web Browser JPG Image DHT Marker Heap Corruption Vulnerability Source: SUSE Type: SUSE-SA:2007:009 opera 9.10 security upgrade | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |