Lucene search

K
cveMitreCVE-2009-3266
HistorySep 18, 2009 - 10:30 p.m.

CVE-2009-3266

2009-09-1822:30:00
CWE-79
mitre
web.nvd.nist.gov
31
opera
xss
cross-site scripting
cross-zone scripting
rss
atom feed
cve-2009-3266
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.005

Percentile

77.4%

Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as “scripted content.”

Affected configurations

Nvd
Node
operaopera_browserMatch5.0
OR
operaopera_browserMatch5.0beta2
OR
operaopera_browserMatch5.0beta3
OR
operaopera_browserMatch5.0beta4
OR
operaopera_browserMatch5.0beta5
OR
operaopera_browserMatch5.0beta6
OR
operaopera_browserMatch5.0beta7
OR
operaopera_browserMatch5.0beta8
OR
operaopera_browserMatch5.02
OR
operaopera_browserMatch5.10
OR
operaopera_browserMatch5.11
OR
operaopera_browserMatch5.12
OR
operaopera_browserMatch6.0
OR
operaopera_browserMatch6.0beta1
OR
operaopera_browserMatch6.0beta2
OR
operaopera_browserMatch6.0tp1
OR
operaopera_browserMatch6.0tp2
OR
operaopera_browserMatch6.0tp3
OR
operaopera_browserMatch6.1
OR
operaopera_browserMatch6.01
OR
operaopera_browserMatch6.1beta1
OR
operaopera_browserMatch6.02
OR
operaopera_browserMatch6.03
OR
operaopera_browserMatch6.04
OR
operaopera_browserMatch6.05
OR
operaopera_browserMatch6.06
OR
operaopera_browserMatch6.11
OR
operaopera_browserMatch6.12
OR
operaopera_browserMatch7.0
OR
operaopera_browserMatch7.0beta1
OR
operaopera_browserMatch7.0beta1_v2
OR
operaopera_browserMatch7.0beta2
OR
operaopera_browserMatch7.01
OR
operaopera_browserMatch7.02
OR
operaopera_browserMatch7.03
OR
operaopera_browserMatch7.10
OR
operaopera_browserMatch7.10beta1
OR
operaopera_browserMatch7.11
OR
operaopera_browserMatch7.11beta2
OR
operaopera_browserMatch7.20
OR
operaopera_browserMatch7.20beta7
OR
operaopera_browserMatch7.21
OR
operaopera_browserMatch7.22
OR
operaopera_browserMatch7.23
OR
operaopera_browserMatch7.50
OR
operaopera_browserMatch7.50beta1
OR
operaopera_browserMatch7.51
OR
operaopera_browserMatch7.52
OR
operaopera_browserMatch7.53
OR
operaopera_browserMatch7.54
OR
operaopera_browserMatch7.54update1
OR
operaopera_browserMatch7.54update2
OR
operaopera_browserMatch7.60
OR
operaopera_browserMatch8.0
OR
operaopera_browserMatch8.0beta1
OR
operaopera_browserMatch8.0beta2
OR
operaopera_browserMatch8.0beta3
OR
operaopera_browserMatch8.01
OR
operaopera_browserMatch8.02
OR
operaopera_browserMatch8.50
OR
operaopera_browserMatch8.51
OR
operaopera_browserMatch8.52
OR
operaopera_browserMatch8.53
OR
operaopera_browserMatch8.54
OR
operaopera_browserMatch9.0
OR
operaopera_browserMatch9.0beta1
OR
operaopera_browserMatch9.0beta2
OR
operaopera_browserMatch9.01
OR
operaopera_browserMatch9.02
OR
operaopera_browserMatch9.10
OR
operaopera_browserMatch9.12
OR
operaopera_browserMatch9.20
OR
operaopera_browserMatch9.20beta1
OR
operaopera_browserMatch9.21
OR
operaopera_browserMatch9.22
OR
operaopera_browserMatch9.23
OR
operaopera_browserMatch9.24
OR
operaopera_browserMatch9.25
OR
operaopera_browserMatch9.26
OR
operaopera_browserMatch9.27
OR
operaopera_browserMatch9.50
OR
operaopera_browserMatch9.50beta1
OR
operaopera_browserMatch9.50beta2
OR
operaopera_browserMatch9.51
OR
operaopera_browserMatch9.52
OR
operaopera_browserMatch9.60
OR
operaopera_browserMatch9.60beta1
OR
operaopera_browserMatch9.61
OR
operaopera_browserMatch9.62
OR
operaopera_browserMatch9.63
OR
operaopera_browserMatch9.64
OR
operaopera_browserMatch10.00
OR
operaopera_browserMatch10.00beta1
OR
operaopera_browserMatch10.00beta2
OR
operaopera_browserMatch10.00beta3
OR
operaopera_browserMatch10.01
OR
operaopera_browserMatch10.10
OR
operaopera_browserMatch10.10beta1
OR
operaopera_browserMatch10.50
OR
operaopera_browserMatch10.50beta1
OR
operaopera_browserMatch10.50beta2
OR
operaopera_browserMatch10.51
OR
operaopera_browserMatch10.52
OR
operaopera_browserMatch10.53
OR
operaopera_browserMatch10.53b
VendorProductVersionCPE
operaopera_browser6.0cpe:/a:opera:opera_browser:6.0:beta2::
operaopera_browser9.63cpe:/a:opera:opera_browser:9.63:::
operaopera_browser8.53cpe:/a:opera:opera_browser:8.53:::
operaopera_browser9.24cpe:/a:opera:opera_browser:9.24:::
operaopera_browser6.1cpe:/a:opera:opera_browser:6.1:beta1::
operaopera_browser9.20cpe:/a:opera:opera_browser:9.20:beta1::
operaopera_browser6.0cpe:/a:opera:opera_browser:6.0:tp1::
operaopera_browser6.05cpe:/a:opera:opera_browser:6.05:::
operaopera_browser5.12cpe:/a:opera:opera_browser:5.12:::
operaopera_browser8.0cpe:/a:opera:opera_browser:8.0:beta3::
Rows per page:
1-10 of 1051

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.005

Percentile

77.4%

Related for CVE-2009-3266