VulnerabilityModified
CVE-2011-0685
The Delete Private Data feature in Opera before 11.01 does not properly implement the "Clear all email account passwords" option, which might allow physically proximate attackers to access an e-mail account via an unattended workstation.
LOW 2.1EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The Delete Private Data feature in Opera before 11.01 does not properly implement the "Clear all email account passwords" option, which might allow physically proximate attackers to access an e-mail account via an unattended workstation.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://osvdb.org/70731
- http://secunia.com/advisories/43023
- http://www.opera.com/docs/changelogs/mac/1101/
- http://www.opera.com/docs/changelogs/unix/1101/
- http://www.opera.com/docs/changelogs/windows/1101/
- http://www.opera.com/support/kb/view/986/Vendor Advisory
- http://www.securityfocus.com/bid/46036
- http://www.vupen.com/english/advisories/2011/0231
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12507
- http://osvdb.org/70731
- http://secunia.com/advisories/43023
- http://www.opera.com/docs/changelogs/mac/1101/
- http://www.opera.com/docs/changelogs/unix/1101/
- http://www.opera.com/docs/changelogs/windows/1101/
- http://www.opera.com/support/kb/view/986/Vendor Advisory
- http://www.securityfocus.com/bid/46036
- http://www.vupen.com/english/advisories/2011/0231
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12507
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.