CVE-2012-3555 describes a vulnerability in Opera versions prior to 11.65, where the browser fails to associate keyboard sequences with visible windows. This flaw, dubbed "hidden keyboard navigation," could be leveraged by user-assisted remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary code through a specially crafted website. With a CVSS score of 7.6, this vulnerability is considered high severity, requiring user interaction (AC:H) but allowing for complete compromise of confidentiality, integrity, and availability (C:C/I:C/A:C) from a network-based attack (AV:N). Despite its potential impact, the EPSS score is very low, indicating a minimal likelihood of exploitation. There is no evidence of active exploitation, nor are there any known public exploits available in Metasploit, Nuclei, or ExploitDB. Furthermore, the vulnerability has garnered no community discussion or media coverage, suggesting a lack of widespread attention or exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.62CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:5.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:5.0:beta2:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:5.0:beta3:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:opera:opera_browser:5.0:beta4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.