WebKit in Apple Safari prior to 5.0 on Mac OS X 10.5 up to and including 10.6 and Windows, and prior to 4.1 on Mac OS X 10.4, does not properly restrict the reading of a canvas that contains an SVG image pattern from a different web site, which allows remote malicious users to read images from other sites via a crafted canvas, related to a "cross-site image capture issue."
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple safari 4.0.4 |
||
apple webkit |
||
apple safari |
||
apple safari 4.0.0b |
||
apple safari 4.0 |
||
apple safari 4.0.3 |
||
apple safari 4.0.2 |
||
apple safari 4.0.1 |