Upstream information
Description
Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
National Vulnerability Database | |
---|---|
Base Score | 4.3 |
Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
SUSE Security Advisories:
- SUSE-SR:2010:014, published Mon, 02 Aug 2010 15:00:00 +0000
- openSUSE-SU-2010:0368-1, published Tue, 13 Jul 2010 23:08:09 +0200 (CEST)
- openSUSE-SU-2010:0370-1, published Tue, 13 Jul 2010 23:08:15 +0200 (CEST)
- openSUSE-SU-2010:0422-1, published Thu, 22 Jul 2010 19:08:22 +0200 (CEST)
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 03:45:14 2013CVE page last modified: Fri Oct 7 12:45:53 2022