Vulnerability Name: | CVE-2010-0051 (CCN-56837) | ||||||||||||
Assigned: | 2009-12-15 | ||||||||||||
Published: | 2010-03-11 | ||||||||||||
Updated: | 2017-09-19 | ||||||||||||
Summary: | WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document. Note: this might overlap CVE-2010-0651. Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html 'WebKit CVE-ID: CVE-2010-0051 Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later, Windows 7, Vista, XP Impact: Visiting a maliciously crafted website may lead to the disclosure of sensitive information Description: An implementation issue exists in WebKit's handling of cross-origin stylesheet requests. Visiting a maliciously crafted website may disclose the content of protected resources on another website. This update addresses the issue by performing additional validation on stylesheets that are loaded during a cross-origin request.' Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html 'Safari 4.0.5 is available via the Apple Software Update application, or Apple's Safari download site at: http://www.apple.com/safari/download/' | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MISC Type: UNKNOWN http://code.google.com/p/chromium/issues/detail?id=9877 Source: MITRE Type: CNA CVE-2010-0051 Source: APPLE Type: UNKNOWN APPLE-SA-2010-11-22-1 Source: APPLE Type: UNKNOWN APPLE-SA-2010-06-21-1 Source: APPLE Type: Vendor Advisory APPLE-SA-2010-03-11-1 Source: SUSE Type: UNKNOWN SUSE-SR:2011:002 Source: OSVDB Type: UNKNOWN 62944 Source: MISC Type: UNKNOWN http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html Source: CCN Type: SA38932 Apple Safari Multiple Vulnerabilities Source: CCN Type: SA39091 Qt WebKit Multiple Vulnerabilities Source: CCN Type: SA40257 Apple iOS Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 41856 Source: CCN Type: SA42314 Apple iOS Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 42314 Source: SECUNIA Type: UNKNOWN 43068 Source: CCN Type: SECTRACK ID: 1023708 Apple Safari WebKit Flaws Let Remote Users Execute Arbitrary Code Source: CCN Type: Apple Web site About the security content of Safari 4.0.5 Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT4070 Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT4225 Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT4456 Source: MISC Type: UNKNOWN http://websec.sv.cmu.edu/css/css.pdf Source: MANDRIVA Type: UNKNOWN MDVSA-2011:039 Source: CCN Type: OSVDB ID: 62944 Apple Safari WebKit CSS Stylesheet Cross-origin Information Disclosure Source: BID Type: Patch 38671 Source: CCN Type: BID-38671 RETIRED: Apple Safari Prior to 4.0.5 Multiple Security Vulnerabilities Source: CCN Type: BID-38692 WebKit Cross-Origin Stylesheet Request Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1023708 Source: UBUNTU Type: UNKNOWN USN-1006-1 Source: VUPEN Type: UNKNOWN ADV-2010-2722 Source: VUPEN Type: UNKNOWN ADV-2011-0212 Source: VUPEN Type: UNKNOWN ADV-2011-0552 Source: CCN Type: Red Hat Bugzilla Bug 570349 CVE-2010-0046, CVE-2010-0047, CVE-2010-0048, CVE-2010-0049, CVE-2010-0050, CVE-2010-0052, CVE-2010-0053, CVE-2010-0054 qt, webkitgtk: multiple security vulnerabilities in WebKit Source: XF Type: UNKNOWN safari-stylesheet-info-disclosure(56837) Source: XF Type: UNKNOWN safari-stylesheet-info-disclosure(56837) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:7554 Source: SUSE Type: SUSE-SR:2011:002 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |