Opera < 9.64 Multiple Vulnerabilities

Medium Nessus Network Monitor Plugin ID 4945


The remote host is vulnerable to multiple attack vectors.


The version of Opera installed on the remote host is earlier than 9.64 and is reportedly affected by multiple issues :

- A memory corruption vulnerability when processing specially crafted JPEG files could allow an attacker to execute arbitrary code with the privileges of the affected application. (926)

- It may be possible for certain plugins to execute arbitrary code in the context of a different domain. An attacker could exploit this to steal authentication credentials as well as carry out other attacks.

- A denial of service issue when the application handles a maliciously crafted web page containing 'HTMLSelectElement' object with a large length attribute.


Upgrade to version 9.64 or higher.

See Also



Plugin Details

Severity: Medium

ID: 4945

File Name: 4945.prm

Family: Web Clients

Published: 2009/03/04

Modified: 2016/01/19

Dependencies: 1735, 8314

Nessus ID: 35761

Risk Information

Risk Factor: Medium


Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 5.6

Temporal Score: 5.2


Temporal Vector: CVSS3#E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:opera:opera_browser

Reference Information

CVE: CVE-2009-0914, CVE-2009-0915, CVE-2009-0916

BID: 33961

OSVDB: 52645, 52646, 52647