CVE-2007-0127
The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.73% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458Patch, Vendor Advisory
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html
- http://osvdb.org/31575
- http://secunia.com/advisories/23613Patch, Vendor Advisory
- http://secunia.com/advisories/23739Vendor Advisory
- http://secunia.com/advisories/23771Vendor Advisory
- http://securitytracker.com/id?1017473
- http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml
- http://www.opera.com/support/search/supsearch.dml?index=851
- http://www.vupen.com/english/advisories/2007/0060
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458Patch, Vendor Advisory
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html
- http://osvdb.org/31575
- http://secunia.com/advisories/23613Patch, Vendor Advisory
- http://secunia.com/advisories/23739Vendor Advisory
- http://secunia.com/advisories/23771Vendor Advisory
- http://securitytracker.com/id?1017473
- http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml
- http://www.opera.com/support/search/supsearch.dml?index=851
- http://www.vupen.com/english/advisories/2007/0060
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.