The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.
http://www.opera.com/support/search/view/861/
http://www.opera.com/docs/changelogs/solaris/922/
http://www.opera.com/docs/changelogs/linux/922/
http://www.opera.com/docs/changelogs/freebsd/922/