The HTML parsing engine in Opera before 9.63 allows remote attackers to execute arbitrary code via crafted web pages that trigger an invalid pointer calculation and heap corruption.
http://www.securitytracker.com/id?1021460
http://www.securityfocus.com/archive/1/499315/100/0/threaded
http://www.opera.com/support/kb/view/921/
http://www.opera.com/docs/changelogs/linux/963/
http://www.nruns.com/security_advisory_opera_html_parsing_code_execution.php
http://securityreason.com/securityalert/4791