Description
Multiple vulnerabilities were found in Opera. Malicious users can exploit these vulnerabilities to bypass security restrictions, spoof user interface, cause denial of service, obtain sensitive information.
Below is a complete list of vulnerabilities:
- Policy enforcement in Extensions component can be exploited via special crafted extension to bypass security restrictions.
- Data validation vulnerability in Blink component can be exploited remotely via special crafted webpage to perform domain spoofing.
- Map processing vulnerability in V8 componenct can be exploited remotely via special crafted webpage to potentially cause denial of service.
- Heap buffer overflow vulnerability in Angle component can be exploited remotely via special crafted webpage to potentially cause denial of service.
- Policy enforcement vulnerability in CORS componenct can be exploited remotely via special crafted webpage to obtain sensitive information.
- Security UI vulnerability in browser component can be exploited remotely via special crafted webpage to perform domain spoofing.
- Data validation vulnerability in URL parser component can be exploited remotely via special craft URL to bypass security restrictions.
- Data validation vulnerability in XMLHttpRequest component can be exploited remotely via special crafted webpage to obtain sensitive information.
- Cross-origin resources size disclosure vulnerability in Appcache component can be exploited remotely via special crafted webpage to obtain sensitive information.
- Security UI vulnerability in popup blocker component on IOS can be exploited via special crafted webpage to bypass security restrictions.
- Out of bounds read vulnerability in Skia component can be exploited remotely via special crafted webpage to potentially obtain sensitive information.
- Out of bounds read vulnerability in Swiftshader component can be exploited remotely via special crafted webpage to potentially cause denial of service.
- Use after free vulnerability in ServiceWorker component can be exploited remotely via special crafted webpage to potentially cause denial of service.
- Use after free vulnerability in Download Manager component can be exploited remotely via special crafted webpage to potentially cause denial of service.
Original advisories
Related products
CVE list
- CVE-2019-5828 high
- CVE-2019-5829 high
- CVE-2019-5830 warning
- CVE-2019-5831 high
- CVE-2019-5832 warning
- CVE-2019-5833 warning
- CVE-2019-5834 warning
- CVE-2019-5835 warning
- CVE-2019-5836 high
- CVE-2019-5837 warning
- CVE-2019-5838 warning
- CVE-2019-5839 warning
- CVE-2019-5840 warning
- CVE-2019-5849 high
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!