Opera before 11.65 does not properly restrict the reading of JSON strings, which allows remote attackers to perform cross-domain loading of JSON resources and consequently obtain sensitive information via a crafted web site.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.