diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index c3f349c2ffbc..7c3685c18f35 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,115 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + opera -- XMLHttpRequest security bypass + + + linux-opera + opera-devel + opera + 8.*8.01 + + + + +

A Secunia Advisory reports:

+
+

Secunia Research has discovered a vulnerability in Opera, + which can be exploited by malicious people to steal + content or to perform actions on other web sites with the + privileges of the user.

+

Normally, it should not be possible for the + XMLHttpRequest object to access resources + from outside the domain of which the object was + opened. However, due to insufficient validation of server + side redirects, it is possible to circumvent this + restriction.

+
+ +
+ + CAN-2005-1475 + http://secunia.com/advisories/15008/ + http://secunia.com/secunia_research/2005-4/advisory/ + http://www.opera.com/freebsd/changelogs/801/#security + + + 2005-06-16 + 2005-06-20 + +
+ + + opera -- "javascript:" URL cross-site scripting + vulnerability + + + linux-opera + opera-devel + opera + 8.01 + + + + +

A Secunia Advisory reports:

+
+

Secunia Research has discovered a vulnerability in Opera, + which can be exploited by malicious people to conduct + cross-site scripting attacks and to read local files.

+

The vulnerability is caused due to Opera not properly + restricting the privileges of "javascript:" URLs when + opened in e.g. new windows or frames.

+
+ +
+ + CAN-2005-1669 + http://secunia.com/advisories/15411/ + http://www.opera.com/freebsd/changelogs/801/#security + + + 2005-06-16 + 2005-06-20 + +
+ + + opera -- redirection cross-site scripting vulnerability + + + linux-opera + opera-devel + opera + 8.*8.01 + + + + +

A Secunia Advisory reports:

+
+

Secunia Research has discovered a vulnerability in Opera, + which can be exploited by malicious people to conduct + cross-site scripting attacks against users.

+

The vulnerability is caused due to input not being + sanitised, when Opera generates a temporary page for + displaying a redirection when "Automatic redirection" is + disabled (not default setting).

+
+ +
+ + http://secunia.com/advisories/15423/ + http://secunia.com/secunia_research/2003-1/advisory/ + http://www.opera.com/freebsd/changelogs/801/#security + + + 2005-06-16 + 2005-06-20 + +
+ sudo -- local race condition vulnerability