VulnerabilityModified
CVE-2005-3006
The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.
MEDIUM 5.0EPSS 2.02%
Does this matter?
Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.
Description
The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=112724692219695&w=2
- http://secunia.com/advisories/16645Patch, Vendor Advisory
- http://secunia.com/secunia_research/2005-42/advisory/Patch, Vendor Advisory
- http://www.opera.com/docs/changelogs/linux/850/
- http://www.opera.com/docs/changelogs/windows/850/
- http://www.osvdb.org/19508Patch
- http://www.securityfocus.com/advisories/9339
- http://www.securityfocus.com/bid/14880
- http://www.vupen.com/english/advisories/2005/1789
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22335
- http://marc.info/?l=bugtraq&m=112724692219695&w=2
- http://secunia.com/advisories/16645Patch, Vendor Advisory
- http://secunia.com/secunia_research/2005-42/advisory/Patch, Vendor Advisory
- http://www.opera.com/docs/changelogs/linux/850/
- http://www.opera.com/docs/changelogs/windows/850/
- http://www.osvdb.org/19508Patch
- http://www.securityfocus.com/advisories/9339
- http://www.securityfocus.com/bid/14880
- http://www.vupen.com/english/advisories/2005/1789
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22335
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.