WebKit in Apple Safari prior to 5.0 on Mac OS X 10.5 up to and including 10.6 and Windows, and prior to 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in unspecified circumstances, which allows man-in-the-middle malicious users to obtain sensitive information via unspecified vectors.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple safari 4.0.1 |
||
apple safari 4.0.0b |
||
apple safari 4.0 |
||
apple safari 4.0.4 |
||
apple safari 4.0.3 |
||
apple safari 4.0.2 |
||
apple webkit |
||
apple safari |