« Volver al listado

CVE-2007-4944

Estado: ModificadaMedia (5)—

The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4944",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-09-18T19:17:00.000",
  "references": [
    {
      "url": "http://osvdb.org/45946",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200708-17.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.opera.com/docs/changelogs/freebsd/922/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.opera.com/docs/changelogs/linux/922/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.opera.com/docs/changelogs/solaris/922/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.opera.com/support/search/view/861/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/45946",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200708-17.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.opera.com/docs/changelogs/freebsd/922/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.opera.com/docs/changelogs/linux/922/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.opera.com/docs/changelogs/solaris/922/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.opera.com/support/search/view/861/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript."
    },
    {
      "lang": "es",
      "value": "La función canvas.createPattern de Opera 9.x versiones anteriores a 9.22 para Linux, FreeBSD, y Solaris no limpia la memoria antes de usarla para procesar un patrón nuevo, lo cual permite a atacantes remotos obtener información confidencial (contenidos de memoria) mediante JavaScript."
    }
  ],
  "lastModified": "2026-06-16T22:45:08.397",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEA17D3F-A17B-47A6-8066-583F63D11468"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76C58A91-23BA-4336-A81B-B7FDFAF6CA91"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC6E40C4-FA29-4D7A-9018-44154503A68F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED63C1B5-F52D-4C70-82D3-B427EAF5CF4F"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98E48C83-01AE-4A33-A004-14B99792674C"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B56A2B78-70BD-439B-B1ED-A17FA5EF0990"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "623E4466-82CC-4BDD-BE25-3BB33B585547"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F90E537-5A0F-4302-9CC3-8EE7EB21DD1D"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.20:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF0002A4-8A90-471C-9813-F648D53E4F3A"
            },
            {
              "criteria": "cpe:2.3:a:opera:opera_browser:9.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5ECA190-D7D3-4248-A61E-0D87E67E3D31"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}