peter bassill · operator
$ cve CVE-2001-0898 JSON

CVE-2001-0898 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript that uses setTimeout to (1) access data after a new window to the domain has been opened or (2) access data via about:cache.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS3.09% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2001-11-15
Last modified2026-06-16

Affected (1)

VendorProduct
opera softwareopera web browser

Public exploits

SourceTitleDate
exploit-dbOpera 5.0/5.1 - Same Origin Policy Circumvention2001-11-15

References

→ the Explorer  ·  watch your stack  ·  NVD