CVE-2008-4795

The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
operaopera
𝑥
≤ 9.61
operaopera
5..10
operaopera
5.0
operaopera
5.1
operaopera
5.2
operaopera
5.3
operaopera
5.4
operaopera
5.5
operaopera
5.6
operaopera
5.7
operaopera
5.8
operaopera
5.9
operaopera
5.11
operaopera
5.12
operaopera
6.0
operaopera
6.01
operaopera
6.02
operaopera
6.03
operaopera
6.04
operaopera
6.05
operaopera
6.06
operaopera
7.0
operaopera
7.0:beta_2
operaopera
7.01
operaopera
7.02
operaopera
7.03
operaopera
7.10
operaopera
7.11
operaopera
7.20
operaopera
7.20:beta7
operaopera
7.21
operaopera
7.22
operaopera
7.23
operaopera
7.50
operaopera
7.50:beta_1
operaopera
7.51
operaopera
7.52
operaopera
7.53
operaopera
7.54
operaopera
7.54:update_1
operaopera
7.54:update_2
operaopera
8.0
operaopera
8.0:beta_1
operaopera
8.0:beta_2
operaopera
8.0:beta_3
operaopera
8.01
operaopera
8.02
operaopera
8.50
operaopera
8.51
operaopera
8.52
operaopera
8.53
operaopera
8.54
operaopera
9.0
operaopera
9.0:beta_1
operaopera
9.0:beta_2
operaopera
9.01
operaopera
9.02
operaopera
9.10
operaopera
9.20
operaopera
9.20:beta_1
operaopera
9.21
operaopera
9.22
operaopera
9.23
operaopera
9.24
operaopera
9.25
operaopera
9.26
operaopera
9.27
operaopera
9.50
operaopera
9.50:beta_2
operaopera
9.51
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opera
intrepid
dne
hardy
dne
gutsy
dne
dapper
dne