CVE-2009-3049 describes a URL spoofing vulnerability in Opera versions prior to 10.00, where the browser failed to correctly display all characters in Internationalized Domain Names (IDN) in the address bar. This flaw could enable remote attackers to conduct phishing attacks by misleading users about the true URL. With a CVSS score of 5.0, this vulnerability is considered medium severity, requiring no authentication and having a low attack complexity, primarily impacting integrity by allowing information spoofing. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.00CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:*:beta_3:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:* | ||
7.23CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:* | ||
7.53CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:7.53:*:*:*:*:*:*:* | ||
7.54CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:7.54:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.