Opera before 10.00, when a collapsed address bar is used, does not properly update the domain name from the previously visited site to the currently visited site, which might allow remote attackers to spoof URLs.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6460
http://www.opera.com/support/kb/view/930/
http://www.opera.com/docs/changelogs/windows/1000/
http://www.opera.com/docs/changelogs/solaris/1000/
http://www.opera.com/docs/changelogs/mac/1000/