4.3
CVSSv2

CVE-2010-3259

Published: 07/09/2010 Updated: 04/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

WebKit, as used in Apple Safari prior to 4.1.3 and 5.0.x prior to 5.0.3, Google Chrome prior to 6.0.472.53, and webkitgtk prior to 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote malicious users to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

webkitgtk webkitgtk

apple safari

apple iphone os

canonical ubuntu linux 9.10

canonical ubuntu linux 10.04

canonical ubuntu linux 10.10

Vendor Advisories

Debian Bug report logs - #599830 Multiple security issues Package: webkit; Maintainer for webkit is (unknown); Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 11 Oct 2010 17:51:09 UTC Severity: grave Tags: security Fixed in version 125-1 Done: Gustavo Noronha Silva <kov@debianorg> Bug is archived N ...