CVE-2013-3210: Opera Browser

Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.

Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.

Affected products

  • Opera Opera Browser: up to and including 12.14; version 3.00 only; version 3.10 only; version 3.21 only; version 3.50 only; version 3.51 only; …

Published 2013-04-19. Last modified 2026-06-16.