VulnerabilityModified
CVE-2004-1489
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
LOW 2.6EPSS 2.01%
Does this matter?
Lower severity and a low EPSS score (2.01%). Track it; it rarely justifies an emergency change on its own.
Description
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 2.01% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-668
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.htmlExploit
- http://www.gentoo.org/security/en/glsa/glsa-200502-17.xmlPatch, Third Party Advisory
- http://www.opera.com/linux/changelogs/754u1/Broken Link
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.htmlExploit
- http://www.gentoo.org/security/en/glsa/glsa-200502-17.xmlPatch, Third Party Advisory
- http://www.opera.com/linux/changelogs/754u1/Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.