Vulnerability Name: | CVE-2010-5070 (CCN-71810) | ||||||||
Assigned: | 2011-12-07 | ||||||||
Published: | 2011-12-07 | ||||||||
Updated: | 2012-03-07 | ||||||||
Summary: | The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different vulnerability than CVE-2010-2264. Note: this may overlap CVE-2010-5073. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-5070 Source: MISC Type: Exploit http://w2spconf.com/2010/papers/p26.pdf Source: CCN Type: The WebKit Open Source Project Web site The WebKit Open Source Project Source: CCN Type: Apple Safari Web site Apple Safari Source: CCN Type: OSVDB ID: 77608 Google Chrome JavaScript Implementation getComputedStyle Method Page Handling Remote Information Disclosure Source: CCN Type: BID-51054 WebKit 'getComputedStyle()' Information Disclosure Vulnerability Source: XF Type: UNKNOWN safari-getcomputedstyle-info-disc(71810) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |