CVE-2011-4690
Last modified
CVE-2011-4690 is a vulnerability of currently unknown severity. Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera Browser | <= 11.60 |
References
- http://secunia.com/advisories/47128Vendor Advisory
- http://secunia.com/advisories/47128Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4690?
How severe is CVE-2011-4690?
How do I fix CVE-2011-4690?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4684Opera before 11.60 does not properly handle certificate revo…
- CVE-2011-4685Dragonfly in Opera before 11.60 allows remote attackers to c…
- CVE-2011-4686Unspecified vulnerability in the Web Workers implementation …
- CVE-2011-4687Opera before 11.60 allows remote attackers to cause a denial…
- CVE-2011-4688Mozilla Firefox 8.0.1 and earlier does not prevent capture o…
- CVE-2011-4689Microsoft Internet Explorer 6 through 9 does not prevent cap…
- CVE-2011-4691Google Chrome 15.0.874.121 and earlier does not prevent capt…
- CVE-2011-4692WebKit, as used in Apple Safari 5.1.1 and earlier and Google…
- CVE-2011-4693Unspecified vulnerability in Adobe Flash Player 11.1.102.55 …
- CVE-2011-4694Unspecified vulnerability in Adobe Flash Player 11.1.102.55 …
- CVE-2011-4695Unspecified vulnerability in Microsoft Windows 7 SP1, when J…
- CVE-2011-4696Directory traversal vulnerability in Eye-Fi Helper before 3.…
Are you affected by CVE-2011-4690?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
