CVE-2009-3832
Estado: ModificadaMedia (5.8)—
Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P
- Puntuación base: 5.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.04%
- Percentil entre todas las CVEs puntuadas: 81
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-601
Referencias
- http://secunia.com/advisories/37182
- http://www.opera.com/docs/changelogs/windows/1001/
- http://www.opera.com/support/kb/view/940/
- http://www.osvdb.org/59359
- http://www.securityfocus.com/bid/36850
- http://www.vupen.com/english/advisories/2009/3073
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54022
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6384
- http://secunia.com/advisories/37182
- http://www.opera.com/docs/changelogs/windows/1001/
- http://www.opera.com/support/kb/view/940/
- http://www.osvdb.org/59359
- http://www.securityfocus.com/bid/36850
- http://www.vupen.com/english/advisories/2009/3073
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54022
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6384
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-3832",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-10-30T20:30:00.467",
"references": [
{
"url": "http://secunia.com/advisories/37182",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.opera.com/docs/changelogs/windows/1001/",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.opera.com/support/kb/view/940/",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/59359",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/36850",
"tags": [
"Broken Link",
"Patch",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/3073",
"tags": [
"Broken Link",
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54022",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6384",
"tags": [
"Tool Signature"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/37182",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.opera.com/docs/changelogs/windows/1001/",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.opera.com/support/kb/view/940/",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/59359",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/36850",
"tags": [
"Broken Link",
"Patch",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2009/3073",
"tags": [
"Broken Link",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54022",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6384",
"tags": [
"Tool Signature"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-601"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site."
},
{
"lang": "es",
"value": "Opera en versiones anteriores a v10.01 corriendo sobre Windows no previene el uso de fuentes web en el renderizado de la interfaz de usuario, lo que permite a atacantes remotos falsificar el campo \"dirección\" a través de una pagina web manipulada."
}
],
"lastModified": "2026-06-16T23:12:26.333",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA8D2696-1A5F-4437-A08E-4374F47894C2",
"versionEndExcluding": "10.01"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}