Vulnerability Description
Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera Browser | 36.0 |
| Opera | Opera Mini | 13.00 |
Related Weaknesses (CWE)
References
- http://abhikafle.com.np/opera-url-spoofing-poc/ExploitThird Party Advisory
- http://www.securityfocus.com/bid/98004Third Party AdvisoryVDB Entry
- http://abhikafle.com.np/opera-url-spoofing-poc/ExploitThird Party Advisory
- http://www.securityfocus.com/bid/98004Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-4075?
CVE-2016-4075 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.
How severe is CVE-2016-4075?
CVE-2016-4075 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4075?
Check the references section above for vendor advisories and patch information. Affected products include: Opera Opera Browser, Opera Opera Mini.