How Opera Software rates security issues

When publishing advisories or details of fixes for security issues that have been uncovered in our products, we rate them according to the potential impact of the issue. To aid understanding, we use terms that are consistent with the terms used by other software vendors. These are applied appropriately to the types of security issue that are relevant to our products. Older advisories used alternative terms, which are also given below.

There are four severity levels that are used for issues that have what we consider to be a security impact. In rare cases, an advisory may also be issued for a bug that has no security impact at all. This gives the final rating, which shows that it is not a security issue. These ratings are typically used in advisories or changelogs.

The terms we use to rate security issues are as follows:

  1. Critical
  2. High
  3. Moderate
  4. Low
  5. None

The following sections give examples of the types of issue that would fall into each rating.

Critical

(Older terms used: extremely severe)

High

(Older terms used: highly severe)

Moderate

(Older terms used: moderately severe)

Low

(Older terms used: less severe)

None

(Older terms used: not severe)

More information

For more details of what we consider a security issue, see our previous article. For details of how we handle security issues that are reported to us, see our security policy. Security issues can be reported securely through the Opera bug tracking system (recommended) or email.

References