NA
CVSSv3

CVE-2010-0051

CVSSv4: NA | CVSSv3: NA | CVSSv2: 4.3 | VMScore: 530 | EPSS: 0.02404 | KEV: Not Included
Published: 15/03/2010 Updated: 21/11/2024

Vulnerability Summary

WebKit in Apple Safari prior to 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote malicious users to obtain sensitive information via a crafted HTML document. NOTE: this might overlap CVE-2010-0651.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari

apple safari 4.0

apple safari 4.0.0b

apple safari 4.0.1

apple safari 4.0.2

apple safari 4.0.3

Vendor Advisories

Debian Bug report logs - #574064 webkit: CVE-2010-0046 through CVE-2010-0054 (multiple vulnerabilities) Package: src:webkit; Maintainer for src:webkit is (unknown); Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Tue, 16 Mar 2010 02:30:01 UTC Severity: grave Tags: security Found in version webkit/101-4 ...

Github Repositories

👨‍⚖️Interview questiones and answers...

前端面试Q&A TypeScript和ES6的区别 TypeScript是一种由微软开发的自由和开源的编程语言。而且本质上向这个语言添加了可选的静态类型和基于类的面向对象编程。安德斯·海尔斯伯格,C#的首席架构师,已工作于TypeScript的开发。TypeScript 是 JavaScript 的超集。TypeScript是为大型应用之开

Thread modeling using Microsoft Threat Modeling Tool Application review Sample application review Architecture review Data flow diagrams Templates Common security issues XSS (Cross-site Scripting) CSRF (Cross-Site Request Forgery) HTTPS interception HSTS resources Thread modeling using Microsoft Threat Modeling Tool Application review users: who the users will be use

References

CWE-20https://nvd.nist.govhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=574064https://github.com/zz570557024/InterView-Q-Ahttps://www.first.org/epsshttp://code.google.com/p/chromium/issues/detail?id=9877http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010/Mar/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/62944http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/42314http://secunia.com/advisories/43068http://support.apple.com/kb/HT4070http://support.apple.com/kb/HT4225http://support.apple.com/kb/HT4456http://websec.sv.cmu.edu/css/css.pdfhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/38671http://www.securitytracker.com/id?1023708http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://exchange.xforce.ibmcloud.com/vulnerabilities/56837https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7554http://code.google.com/p/chromium/issues/detail?id=9877http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010/Mar/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/62944http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/42314http://secunia.com/advisories/43068http://support.apple.com/kb/HT4070http://support.apple.com/kb/HT4225http://support.apple.com/kb/HT4456http://websec.sv.cmu.edu/css/css.pdfhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/38671http://www.securitytracker.com/id?1023708http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://exchange.xforce.ibmcloud.com/vulnerabilities/56837https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7554