CVE-2007-4944
Last modified
CVE-2007-4944 is a vulnerability of currently unknown severity. The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.. EPSS estimates a 2.14% chance of exploitation in the next 30 days.
Description
The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera Browser | 9.0 |
| Opera | Opera Browser | 9.01 |
| Opera | Opera Browser | 9.02 |
| Opera | Opera Browser | 9.10 |
| Opera | Opera Browser | 9.12 |
| Opera | Opera Browser | 9.20 |
| Opera | Opera Browser | 9.21 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4944?
How severe is CVE-2007-4944?
How do I fix CVE-2007-4944?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4938Heap-based buffer overflow in libmpdemux/aviheader.c in MPla…
- CVE-2007-4939Heap-based buffer overflow in mplayerc.exe in Media Player C…
- CVE-2007-4940Multiple integer overflows in Media Player Classic (MPC) 6.4…
- CVE-2007-4941KMPlayer 2.9.3.1210 and earlier allows remote attackers to c…
- CVE-2007-4942PHP remote file inclusion vulnerability in modules/Disciplin…
- CVE-2007-4943Multiple buffer overflows in a certain ActiveX control in sp…
- CVE-2007-4945Multiple cross-site scripting (XSS) vulnerabilities in Lette…
- CVE-2007-4946LetterGrade allows remote attackers to obtain sensitive info…
- CVE-2007-4947Multiple PHP remote file inclusion vulnerabilities in myphpP…
- CVE-2007-4948Multiple PHP remote file inclusion vulnerabilities in Webmed…
- CVE-2007-4949Multiple PHP remote file inclusion vulnerabilities in php(Re…
- CVE-2007-4950PHP remote file inclusion vulnerability in form/db_form/empl…
Are you affected by CVE-2007-4944?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
