4.3
CVSSv2

CVE-2010-0651

Published: 18/02/2010 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

WebKit before r52784, as used in Google Chrome prior to 4.0.249.78 and Apple Safari prior to 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote malicious users to obtain sensitive information via a crafted document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple webkit

google chrome

apple safari

Vendor Advisories

Debian Bug report logs - #574064 webkit: CVE-2010-0046 through CVE-2010-0054 (multiple vulnerabilities) Package: src:webkit; Maintainer for src:webkit is (unknown); Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Tue, 16 Mar 2010 02:30:01 UTC Severity: grave Tags: security Found in version webkit/101-4 ...