CVE-2011-2628: Input Validation
Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2628?
CVE-2011-2628 is classified as a critical vulnerability due to its potential for arbitrary code execution and denial of service.
How do I fix CVE-2011-2628?
To mitigate CVE-2011-2628, users should upgrade to Opera version 11.11 or later where the vulnerability is addressed.
What versions of Opera are affected by CVE-2011-2628?
CVE-2011-2628 affects multiple versions of Opera prior to 11.11, including versions as early as 5.0.
What types of attacks can exploit CVE-2011-2628?
CVE-2011-2628 can be exploited through specially crafted webpages that trigger memory corruption in the browser.
Is there any workaround for CVE-2011-2628?
The best workaround for CVE-2011-2628 is to disable JavaScript in the browser settings until an upgrade can be performed.