CVE-2007-2274
CVE-2007-2274 is a high-severity vulnerability in Opera Opera Browser with a CVSS 2.0 base score of 7.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-401.
Key facts
- Severity: High (CVSS 2.0 base score 7.8)
- EPSS exploit prediction: 8% (94th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-401
- Affected product: Opera Opera Browser
- Published:
- Last modified:
Description
The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the original disclosure refers to this as a memory leak, but it is not certain.
Frequently asked questions
- What is CVE-2007-2274?
- The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the original disclosure refers to this as a memory leak, but it is not certain.
- How severe is CVE-2007-2274?
- CVE-2007-2274 has a CVSS 2.0 base score of 7.8, rated high severity.
- Is CVE-2007-2274 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 8% (94th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2007-2274?
- CVE-2007-2274 affects Opera Opera Browser. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2007-2274?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2007-2274 published?
- CVE-2007-2274 was published on 2007-04-25 and last updated on 2026-06-16.
References
Affected products (1)
- cpe:2.3:a:opera:opera_browser:9.2:*:*:*:*:*:*:*
More vulnerabilities in Opera Opera Browser
- CVE-2013-3211 — Critical (CVSS 10.0): Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe…
- CVE-2012-4145 — Critical (CVSS 10.0): Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS…
- CVE-2012-3561 — Critical (CVSS 10.0): Opera before 11.64 does not properly allocate memory for URL strings, which allows remote attackers to execute…
- CVE-2012-3559 — Critical (CVSS 10.0): Unspecified vulnerability in Opera before 12.00 on Mac OS X has unknown impact and attack vectors, related to a…
- CVE-2011-4684 — Critical (CVSS 10.0): Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack…
- CVE-2011-4683 — Critical (CVSS 10.0): Unspecified vulnerability in Opera before 11.60 has unknown impact and attack vectors, related to a "moderately severe…
All CVEs affecting Opera Opera Browser →
Other CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities
- CVE-2026-46289 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in…
- CVE-2025-39948 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The…
- CVE-2025-21954 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently…
- CVE-2024-57947 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map…
- CVE-2024-56779 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent…
- CVE-2024-36911 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo…
Browse all CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities →