VulnerabilityModified
CVE-2005-2405
Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing…
MEDIUM 5.0EPSS 2.78%
Does this matter?
Lower severity and a low EPSS score (2.78%). Track it; it rarely justifies an emergency change on its own.
Description
Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.78% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/15870Broken Link, Patch
- http://securitytracker.com/id?1014592Broken Link, Third Party Advisory, VDB Entry
- http://www.opera.com/linux/changelogs/802/Broken Link, Patch
- http://www.securityfocus.com/bid/14402Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2005/1251Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21784Third Party Advisory, VDB Entry
- http://secunia.com/advisories/15870Broken Link, Patch
- http://securitytracker.com/id?1014592Broken Link, Third Party Advisory, VDB Entry
- http://www.opera.com/linux/changelogs/802/Broken Link, Patch
- http://www.securityfocus.com/bid/14402Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2005/1251Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21784Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.