First published: Fri Sep 18 2009(Updated: )
Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | =7.01 | |
Opera | =9.27 | |
Opera | =7.23 | |
Opera | =9.50-beta1 | |
Opera | =9.02 | |
Opera | =10.53-b | |
Opera | =7.03 | |
Opera | =10.10 | |
Opera | =7.53 | |
Opera | =8.50 | |
Opera | =9.50 | |
Opera | =9.24 | |
Opera | =5.0-beta2 | |
Opera | =5.11 | |
Opera | =9.63 | |
Opera | =6.1 | |
Opera | =7.20 | |
Opera | =6.02 | |
Opera | =9.51 | |
Opera | =5.02 | |
Opera | =10.00 | |
Opera | =9.26 | |
Opera | =10.50 | |
Opera | =5.10 | |
Opera | =8.53 | |
Opera | =9.12 | |
Opera | =7.11-beta2 | |
Opera | =8.0 | |
Opera | =10.00-beta3 | |
Opera | =6.04 | |
Opera | =8.54 | |
Opera | =6.11 | |
Opera | =5.0-beta4 | |
Opera | =6.05 | |
Opera | =8.02 | |
Opera | =9.20 | |
Opera | =7.50-beta1 | |
Opera | =5.12 | |
Opera | =9.21 | |
Opera | =7.10 | |
Opera | =9.0-beta1 | |
Opera | =6.0-tp3 | |
Opera | =9.23 | |
Opera | =6.0-tp1 | |
Opera | =8.0-beta3 | |
Opera | =5.0-beta8 | |
Opera | =10.52 | |
Opera | =10.51 | |
Opera | =9.60 | |
Opera | =7.0-beta1_v2 | |
Opera | =8.51 | |
Opera | =5.0-beta5 | |
Opera | =7.50 | |
Opera | =7.02 | |
Opera | =7.21 | |
Opera | =6.0-tp2 | |
Opera | =5.0-beta7 | |
Opera | =10.50-beta1 | |
Opera | =7.20-beta7 | |
Opera | =7.54-update1 | |
Opera | =9.64 | |
Opera | =9.20-beta1 | |
Opera | =10.53 | |
Opera | =7.60 | |
Opera | =7.11 | |
Opera | =7.0-beta2 | |
Opera | =7.54 | |
Opera | =9.0-beta2 | |
Opera | =6.03 | |
Opera | =7.0-beta1 | |
Opera | =9.22 | |
Opera | =6.0-beta1 | |
Opera | =9.01 | |
Opera | =9.0 | |
Opera | =5.0 | |
Opera | =9.25 | |
Opera | =7.51 | |
Opera | =8.0-beta2 | |
Opera | =9.10 | |
Opera | =10.00-beta1 | |
Opera | =9.50-beta2 | |
Opera | =6.12 | |
Opera | =9.60-beta1 | |
Opera | =9.62 | |
Opera | =10.00-beta2 | |
Opera | =6.0-beta2 | |
Opera | =5.0-beta3 | |
Opera | =6.01 | |
Opera | =8.52 | |
Opera | =10.50-beta2 | |
Opera | =6.06 | |
Opera | =7.52 | |
Opera | =7.54-update2 | |
Opera | =5.0-beta6 | |
Opera | =8.01 | |
Opera | =6.1-beta1 | |
Opera | =10.10-beta1 | |
Opera | =9.61 | |
Opera | =10.01 | |
Opera | =9.52 | |
Opera | =8.0-beta1 | |
Opera | =6.0 | |
Opera | =7.22 | |
Opera | =7.10-beta1 | |
Opera | =7.0 | |
Web Browser for Android | =5.0 | |
Web Browser for Android | =5.0-beta2 | |
Web Browser for Android | =5.0-beta3 | |
Web Browser for Android | =5.0-beta4 | |
Web Browser for Android | =5.0-beta5 | |
Web Browser for Android | =5.0-beta6 | |
Web Browser for Android | =5.0-beta7 | |
Web Browser for Android | =5.0-beta8 | |
Web Browser for Android | =5.02 | |
Web Browser for Android | =5.10 | |
Web Browser for Android | =5.11 | |
Web Browser for Android | =5.12 | |
Web Browser for Android | =6.0 | |
Web Browser for Android | =6.0-beta1 | |
Web Browser for Android | =6.0-beta2 | |
Web Browser for Android | =6.0-tp1 | |
Web Browser for Android | =6.0-tp2 | |
Web Browser for Android | =6.0-tp3 | |
Web Browser for Android | =6.1 | |
Web Browser for Android | =6.01 | |
Web Browser for Android | =6.1-beta1 | |
Web Browser for Android | =6.02 | |
Web Browser for Android | =6.03 | |
Web Browser for Android | =6.04 | |
Web Browser for Android | =6.05 | |
Web Browser for Android | =6.06 | |
Web Browser for Android | =6.11 | |
Web Browser for Android | =6.12 | |
Web Browser for Android | =7.0 | |
Web Browser for Android | =7.0-beta1 | |
Web Browser for Android | =7.0-beta1_v2 | |
Web Browser for Android | =7.0-beta2 | |
Web Browser for Android | =7.01 | |
Web Browser for Android | =7.02 | |
Web Browser for Android | =7.03 | |
Web Browser for Android | =7.10 | |
Web Browser for Android | =7.10-beta1 | |
Web Browser for Android | =7.11 | |
Web Browser for Android | =7.11-beta2 | |
Web Browser for Android | =7.20 | |
Web Browser for Android | =7.20-beta7 | |
Web Browser for Android | =7.21 | |
Web Browser for Android | =7.22 | |
Web Browser for Android | =7.23 | |
Web Browser for Android | =7.50 | |
Web Browser for Android | =7.50-beta1 | |
Web Browser for Android | =7.51 | |
Web Browser for Android | =7.52 | |
Web Browser for Android | =7.53 | |
Web Browser for Android | =7.54 | |
Web Browser for Android | =7.54-update1 | |
Web Browser for Android | =7.54-update2 | |
Web Browser for Android | =7.60 | |
Web Browser for Android | =8.0 | |
Web Browser for Android | =8.0-beta1 | |
Web Browser for Android | =8.0-beta2 | |
Web Browser for Android | =8.0-beta3 | |
Web Browser for Android | =8.01 | |
Web Browser for Android | =8.02 | |
Web Browser for Android | =8.50 | |
Web Browser for Android | =8.51 | |
Web Browser for Android | =8.52 | |
Web Browser for Android | =8.53 | |
Web Browser for Android | =8.54 | |
Web Browser for Android | =9.0 | |
Web Browser for Android | =9.0-beta1 | |
Web Browser for Android | =9.0-beta2 | |
Web Browser for Android | =9.01 | |
Web Browser for Android | =9.02 | |
Web Browser for Android | =9.10 | |
Web Browser for Android | =9.12 | |
Web Browser for Android | =9.20 | |
Web Browser for Android | =9.20-beta1 | |
Web Browser for Android | =9.21 | |
Web Browser for Android | =9.22 | |
Web Browser for Android | =9.23 | |
Web Browser for Android | =9.24 | |
Web Browser for Android | =9.25 | |
Web Browser for Android | =9.26 | |
Web Browser for Android | =9.27 | |
Web Browser for Android | =9.50 | |
Web Browser for Android | =9.50-beta1 | |
Web Browser for Android | =9.50-beta2 | |
Web Browser for Android | =9.51 | |
Web Browser for Android | =9.52 | |
Web Browser for Android | =9.60 | |
Web Browser for Android | =9.60-beta1 | |
Web Browser for Android | =9.61 | |
Web Browser for Android | =9.62 | |
Web Browser for Android | =9.63 | |
Web Browser for Android | =9.64 | |
Web Browser for Android | =10.00 | |
Web Browser for Android | =10.00-beta1 | |
Web Browser for Android | =10.00-beta2 | |
Web Browser for Android | =10.00-beta3 | |
Web Browser for Android | =10.01 | |
Web Browser for Android | =10.10 | |
Web Browser for Android | =10.10-beta1 | |
Web Browser for Android | =10.50 | |
Web Browser for Android | =10.50-beta1 | |
Web Browser for Android | =10.50-beta2 | |
Web Browser for Android | =10.51 | |
Web Browser for Android | =10.52 | |
Web Browser for Android | =10.53 | |
Web Browser for Android | =10.53-b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3266 has a high severity rating due to its potential for allowing remote cross-site scripting (XSS) attacks.
To fix CVE-2009-3266, upgrade to Opera version 10.01 or later, which addresses this vulnerability.
The consequences of CVE-2009-3266 include the ability for attackers to conduct XSS attacks and manipulate feed subscriptions.
CVE-2009-3266 affects multiple versions of Opera prior to 10.01, including version 7.x and 9.x.
CVE-2009-3266 exploits the insufficient restriction of HTML in RSS and Atom feeds to execute malicious scripts.