Opera < 9.64 Multiple Vulnerabilities

High Log Correlation Engine Plugin ID 800824


The remote host is vulnerable to multiple attack vectors.


The version of Opera installed on the remote host is earlier than 9.64 and is reportedly affected by multiple issues :

- A memory corruption vulnerability when processing specially crafted JPEG files could allow an attacker to execute arbitrary code with the privileges of the affected application. (926)

- It may be possible for certain plugins to execute arbitrary code in the context of a different domain. An attacker could exploit this to steal authentication credentials as well as carry out other attacks.

- A denial of service issue when the application handles a maliciously crafted web page containing 'HTMLSelectElement' object with a large length attribute.


Upgrade to version 9.64 or higher.

See Also



Plugin Details

Severity: High

ID: 800824

File Name: 800824.prm

Family: Web Clients

Nessus ID: 35761

Risk Information

Risk Factor: High


Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Reference Information

CVE: CVE-2009-0914, CVE-2009-0915, CVE-2009-0916

BID: 33961