CVE-2008-4197
Last modified
CVE-2008-4197 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.. EPSS estimates a 6.33% chance of exploitation in the next 30 days.
Description
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera Browser | < 9.52 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=235298Issue Tracking
- http://secunia.com/advisories/31549Broken Link, Vendor Advisory
- http://secunia.com/advisories/32538Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200811-01.xmlThird Party Advisory
- http://www.securityfocus.com/bid/30768Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020720Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44552Third Party Advisory, VDB Entry
- http://bugs.gentoo.org/show_bug.cgi?id=235298Issue Tracking
- http://secunia.com/advisories/31549Broken Link, Vendor Advisory
- http://secunia.com/advisories/32538Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200811-01.xmlThird Party Advisory
- http://www.securityfocus.com/bid/30768Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020720Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44552Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4197?
How severe is CVE-2008-4197?
How do I fix CVE-2008-4197?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4191extract-table.pl in Emacspeak 26 and 28 allows local users t…
- CVE-2008-4192The pserver_shutdown function in fence_egenera in cman 2.200…
- CVE-2008-4193Stack-based buffer overflow in SecurityGateway.dll in Alt-N …
- CVE-2008-4194The p_exec_query function in src/dns_query.c in pdnsd before…
- CVE-2008-4195Opera before 9.52 does not properly restrict the ability of …
- CVE-2008-4196Cross-site scripting (XSS) vulnerability in Opera before 9.5…
- CVE-2008-4198Opera before 9.52, when rendering an http page that has load…
- CVE-2008-4199Opera before 9.52 does not prevent use of links from web pag…
- CVE-2008-4200Opera before 9.52 does not ensure that the address field of …
- CVE-2008-4201Heap-based buffer overflow in the decodeMP4file function (fr…
- CVE-2008-4202SQL injection vulnerability in index.php in Gonafish LinksCa…
- CVE-2008-4203SQL injection vulnerability in cn_users.php in CzarNews 1.20…
Are you affected by CVE-2008-4197?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
