Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which triggers an out-of-bounds operation.
https://exchange.xforce.ibmcloud.com/vulnerabilities/27289
https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-3196
http://www.vupen.com/english/advisories/2006/2617
http://www.securityfocus.com/bid/18585
http://www.securityfocus.com/archive/1/438326/100/0/threaded
http://www.securityfocus.com/archive/1/437945/100/0/threaded
http://www.critical.lt/?vuln/349