CVE-2008-4199
Last modified
CVE-2008-4199 is a vulnerability of currently unknown severity. Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filenames via vectors involving "detection of JavaScript events and appropriate manipulation.". EPSS estimates a 2.86% chance of exploitation in the next 30 days.
Description
Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filenames via vectors involving "detection of JavaScript events and appropriate manipulation."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera Browser | <= 9.51 |
| Opera | Opera Browser | 5.0 |
| Opera | Opera Browser | 5.02 |
| Opera | Opera Browser | 5.10 |
| Opera | Opera Browser | 5.11 |
| Opera | Opera Browser | 5.12 |
| Opera | Opera Browser | 6.0 |
| Opera | Opera Browser | 6.1 |
| Opera | Opera Browser | 6.01 |
| Opera | Opera Browser | 6.02 |
| Opera | Opera Browser | 6.03 |
| Opera | Opera Browser | 6.04 |
| Opera | Opera Browser | 6.05 |
| Opera | Opera Browser | 6.06 |
| Opera | Opera Browser | 6.11 |
| Opera | Opera Browser | 6.12 |
| Opera | Opera Browser | 7.0 |
| Opera | Opera Browser | 7.01 |
| Opera | Opera Browser | 7.02 |
| Opera | Opera Browser | 7.03 |
| Opera | Opera Browser | 7.10 |
| Opera | Opera Browser | 7.11 |
| Opera | Opera Browser | 7.20 |
| Opera | Opera Browser | 7.21 |
| Opera | Opera Browser | 7.22 |
| Opera | Opera Browser | 7.23 |
| Opera | Opera Browser | 7.50 |
| Opera | Opera Browser | 7.51 |
| Opera | Opera Browser | 7.52 |
| Opera | Opera Browser | 7.53 |
| Opera | Opera Browser | 7.54 |
| Opera | Opera Browser | 7.60 |
| Opera | Opera Browser | 8.0 |
| Opera | Opera Browser | 8.01 |
| Opera | Opera Browser | 8.02 |
| Opera | Opera Browser | 8.50 |
| Opera | Opera Browser | 8.51 |
| Opera | Opera Browser | 8.52 |
| Opera | Opera Browser | 8.53 |
| Opera | Opera Browser | 8.54 |
| Opera | Opera Browser | 9.0 |
| Opera | Opera Browser | 9.01 |
| Opera | Opera Browser | 9.02 |
| Opera | Opera Browser | 9.10 |
| Opera | Opera Browser | 9.12 |
| Opera | Opera Browser | 9.20 |
| Opera | Opera Browser | 9.21 |
| Opera | Opera Browser | 9.22 |
| Opera | Opera Browser | 9.23 |
| Opera | Opera Browser | 9.24 |
Showing 50 of 54 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/31549Vendor Advisory
- http://secunia.com/advisories/32538Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2416Vendor Advisory
- http://secunia.com/advisories/31549Vendor Advisory
- http://secunia.com/advisories/32538Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2416Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4199?
How severe is CVE-2008-4199?
How do I fix CVE-2008-4199?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4193Stack-based buffer overflow in SecurityGateway.dll in Alt-N …
- CVE-2008-4194The p_exec_query function in src/dns_query.c in pdnsd before…
- CVE-2008-4195Opera before 9.52 does not properly restrict the ability of …
- CVE-2008-4196Cross-site scripting (XSS) vulnerability in Opera before 9.5…
- CVE-2008-4197Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, w…8.8
- CVE-2008-4198Opera before 9.52, when rendering an http page that has load…
- CVE-2008-4200Opera before 9.52 does not ensure that the address field of …
- CVE-2008-4201Heap-based buffer overflow in the decodeMP4file function (fr…
- CVE-2008-4202SQL injection vulnerability in index.php in Gonafish LinksCa…
- CVE-2008-4203SQL injection vulnerability in cn_users.php in CzarNews 1.20…
- CVE-2008-4204SQL injection vulnerability in city.asp in SoftAcid Hotel Re…
- CVE-2008-4205SQL injection vulnerability in search.php Attachmax Dolphin …
Are you affected by CVE-2008-4199?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
