vendor:
Opera 12.15
by:
echo
7,5
CVSS
HIGH
VTable Corruption
119
CWE
Product Name: Opera 12.15
Affected Version From: 12.15
Affected Version To: 12.15
Patch Exists: Yes
Related CWE: N/A
CPE: opera:opera_12.15
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x64
2014
Opera 12.15 DOS POC
Opera 12.15 is vulnerable to a Denial of Service attack due to a VTable Corruption vulnerability. The vulnerability occurs when a frame and meter element are created and appended to the document body. When the getBoundingClientRect() method is called on the frame element, the VTable of the meter element is corrupted, causing the code to crash.
Mitigation:
Upgrade to the latest version of Opera 12.15 or later.