CVE-2012-6462: Opera Browser

Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.

Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request.

Affected products

  • Opera Opera Browser: up to and including 12.10; version 1.00 only; version 2.00 only; version 2.10 only; version 2.12 only; version 3.00 only; …

Published 2013-01-02. Last modified 2026-06-16.