{"api_version":"1","generated_at":"2026-07-23T04:19:43+00:00","cve":"CVE-2011-4690","urls":{"html":"https://cve.report/CVE-2011-4690","api":"https://cve.report/api/cve/CVE-2011-4690.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-4690","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-4690"},"summary":{"title":"CVE-2011-4690","description":"Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-12-07 19:55:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://lcamtuf.coredump.cx/cachetime/","name":"http://lcamtuf.coredump.cx/cachetime/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Rapid history extraction through non-destructive cache timing (v8)","mime":"text/html","httpstatus":"200","archivestatus":"403"},{"url":"http://secunia.com/advisories/47128","name":"http://secunia.com/advisories/47128","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-4690","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4690","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"4690","vulnerable":"1","versionEndIncluding":"11.60","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera","cpe5":"opera_browser","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:16:33.426Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"47128","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/47128"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lcamtuf.coredump.cx/cachetime/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-12-07T19:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"47128","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/47128"},{"tags":["x_refsource_MISC"],"url":"http://lcamtuf.coredump.cx/cachetime/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-4690","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"47128","refsource":"SECUNIA","url":"http://secunia.com/advisories/47128"},{"name":"http://lcamtuf.coredump.cx/cachetime/","refsource":"MISC","url":"http://lcamtuf.coredump.cx/cachetime/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-4690","datePublished":"2011-12-07T19:00:00.000Z","dateReserved":"2011-12-07T00:00:00.000Z","dateUpdated":"2024-09-17T04:09:06.098Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-12-07 19:55:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*","versionEndIncluding":"11.60","matchCriteriaId":"E30031BF-B34D-4508-A5AB-FB6C7388A864"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"4690","Ordinal":"1","Title":"CVE-2011-4690","CVE":"CVE-2011-4690","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"4690","Ordinal":"1","NoteData":"Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.","Type":"Description","Title":"CVE-2011-4690"},{"CveYear":"2011","CveId":"4690","Ordinal":"2","NoteData":"2011-12-07","Type":"Other","Title":"Published"}]}}}