10
CVSSv2

CVE-2010-1760

Published: 19/08/2010 Updated: 18/03/2011
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.

Vulnerable Product Search on Vulmon Subscribe to Product

apple webkit

apple webkit r56188

apple webkit r56379

apple webkit r50173

apple webkit r56187