VulnerabilityModified
CVE-2009-3832
Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site.
MEDIUM 5.8EPSS 2.04%
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/37182Broken Link
- http://www.opera.com/docs/changelogs/windows/1001/Broken Link, Vendor Advisory
- http://www.opera.com/support/kb/view/940/Broken Link, Vendor Advisory
- http://www.osvdb.org/59359Broken Link
- http://www.securityfocus.com/bid/36850Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/3073Broken Link, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54022Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6384Tool Signature
- http://secunia.com/advisories/37182Broken Link
- http://www.opera.com/docs/changelogs/windows/1001/Broken Link, Vendor Advisory
- http://www.opera.com/support/kb/view/940/Broken Link, Vendor Advisory
- http://www.osvdb.org/59359Broken Link
- http://www.securityfocus.com/bid/36850Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/3073Broken Link, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54022Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6384Tool Signature
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.