CVE-2008-3078

Opera < 9.51 - Uninitialized Memory Exposure via CANVAS Element

Title source: llm
STIX 2.1

Description

Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized memory contents by using JavaScript to read a canvas image.

References (12)

Core 12
Core References
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/mac/951/
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/windows/951/
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/freebsd/951/
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/linux/951/
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/solaris/951/
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30935
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30068
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43575
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1997/references
Vendor Advisory x_refsource_confirm
http://www.opera.com/support/search/view/887/
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31339

Scores

EPSS 0.0100
EPSS Percentile 77.2%

Details

CWE
CWE-200
Status published
Products (27)
opera/opera_browser 1.00
opera/opera_browser 2.00
opera/opera_browser 2.10 (4 CPE variants)
opera/opera_browser 2.12
opera/opera_browser 3.00 (2 CPE variants)
opera/opera_browser 3.10
opera/opera_browser 3.21
opera/opera_browser 3.50
opera/opera_browser 3.51
opera/opera_browser 3.60
... and 17 more
Published Jul 09, 2008
Tracked Since Feb 18, 2026