Vulnerability Name: | CVE-2010-0652 (CCN-56431) | ||||||||
Assigned: | 2010-01-25 | ||||||||
Published: | 2010-01-25 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Microsoft Internet Explorer permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: Google Code Web site Issue 9877:Security: cross domain thefts via CSS string property injection Source: MISC Type: Exploit http://code.google.com/p/chromium/issues/detail?id=9877 Source: MITRE Type: CNA CVE-2010-0652 Source: CCN Type: Microsoft Web site Microsoft Internet Explorer Source: CCN Type: OSVDB ID: 62466 Microsoft IE CSS Stylesheet Cross-origin Information Disclosure Source: XF Type: UNKNOWN ie-css-stylesheets-info-disclsoure(56431) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |