Opera before 9.63 does not block unspecified "scripted URLs" during the feed preview, which allows remote attackers to read existing subscriptions and force subscriptions to arbitrary feed URLs.
http://www.securitytracker.com/id?1021461
http://www.opera.com/support/kb/view/923/
http://www.opera.com/docs/changelogs/linux/963/