CVE-2010-4045: XSS
Opera before 10.63 does not properly restrict web script in unspecified circumstances involving reloads and redirects, which allows remote attackers to spoof the Address Bar, conduct cross-site scripting (XSS) attacks, and possibly execute arbitrary code by leveraging the ability of a script to interact with a web page from (1) a different domain or (2) a different security context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4045?
CVE-2010-4045 is considered a medium severity vulnerability due to its potential for executing cross-site scripting (XSS) attacks and eavesdropping.
How do I fix CVE-2010-4045?
To fix CVE-2010-4045, users should upgrade to Opera browser version 10.63 or later.
What types of attacks can exploit CVE-2010-4045?
CVE-2010-4045 can be exploited for Address Bar spoofing and cross-site scripting (XSS) attacks.
Which versions of Opera are affected by CVE-2010-4045?
CVE-2010-4045 affects Opera versions prior to 10.63 including 10.62 and earlier versions.
Can CVE-2010-4045 allow arbitrary code execution?
Yes, CVE-2010-4045 may allow remote attackers to execute arbitrary code by leveraging its vulnerabilities.