CVE-2008-4795

EUVD-2008-4774
The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
operaopera
𝑥
≤ 9.61
operaopera
5..10
operaopera
5.0
operaopera
5.1
operaopera
5.2
operaopera
5.3
operaopera
5.4
operaopera
5.5
operaopera
5.6
operaopera
5.7
operaopera
5.8
operaopera
5.9
operaopera
5.11
operaopera
5.12
operaopera
6.0
operaopera
6.01
operaopera
6.02
operaopera
6.03
operaopera
6.04
operaopera
6.05
operaopera
6.06
operaopera
7.0
operaopera
7.0:beta_2
operaopera
7.01
operaopera
7.02
operaopera
7.03
operaopera
7.10
operaopera
7.11
operaopera
7.20
operaopera
7.20:beta7
operaopera
7.21
operaopera
7.22
operaopera
7.23
operaopera
7.50
operaopera
7.50:beta_1
operaopera
7.51
operaopera
7.52
operaopera
7.53
operaopera
7.54
operaopera
7.54:update_1
operaopera
7.54:update_2
operaopera
8.0
operaopera
8.0:beta_1
operaopera
8.0:beta_2
operaopera
8.0:beta_3
operaopera
8.01
operaopera
8.02
operaopera
8.50
operaopera
8.51
operaopera
8.52
operaopera
8.53
operaopera
8.54
operaopera
9.0
operaopera
9.0:beta_1
operaopera
9.0:beta_2
operaopera
9.01
operaopera
9.02
operaopera
9.10
operaopera
9.20
operaopera
9.20:beta_1
operaopera
9.21
operaopera
9.22
operaopera
9.23
operaopera
9.24
operaopera
9.25
operaopera
9.26
operaopera
9.27
operaopera
9.50
operaopera
9.50:beta_2
operaopera
9.51
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opera
dapper
dne
gutsy
dne
hardy
dne
intrepid
dne