CVE-2011-3388

Opera < 11.51 - Unauthenticated Exposure of Sensitive Information via Extended Validation Spoofing

Title source: llm
STIX 2.1

Description

Opera before 11.51 allows remote attackers to cause an insecure site to appear secure or trusted via unspecified actions related to Extended Validation and loading content from trusted sources in an unspecified sequence that causes the address field and page information dialog to contain security information based on the trusted site, instead of the insecure site.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025997
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/49388
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/74828
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/windows/1151/
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45791
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/unix/1151/
Vendor Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/mac/1151/
Vendor Advisory x_refsource_confirm
http://www.opera.com/support/kb/view/1000/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/69515

Scores

EPSS 0.0100
EPSS Percentile 77.3%

Details

CWE
CWE-200
Status published
Products (30)
opera/opera_browser 5.0 (8 CPE variants)
opera/opera_browser 5.02
opera/opera_browser 5.10
opera/opera_browser 5.11
opera/opera_browser 5.12
opera/opera_browser 6.0 (6 CPE variants)
opera/opera_browser 6.1 (2 CPE variants)
opera/opera_browser 6.01
opera/opera_browser 6.02
opera/opera_browser 6.03
... and 20 more
Published Sep 06, 2011
Tracked Since Feb 18, 2026