The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade opera-develUpgrade operaUpgrade linux-opera | Dec 10, 2025 | Jan 5, 2007 |
| Gentoo Linux | — | Upgrade www-client/opera. | Oct 30, 2017 | Jan 8, 2007 |
| Suse | — | Upgrade operaUpgrade suse-release | Feb 17, 2015 | Jan 8, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub