CVE-2010-0051 Information
Description
WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets which allows remote attackers to obtain sensitive information via a crafted HTML document. NOTE: this might overlap CVE-2010-0651.
Reference
http://code.google.com/p/chromium/issues/detail?id=9877 http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html http://osvdb.org/62944 http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html http://secunia.com/advisories/41856 http://secunia.com/advisories/42314 http://secunia.com/advisories/43068 http://support.apple.com/kb/HT4070 http://support.apple.com/kb/HT4225 http://support.apple.com/kb/HT4456 http://websec.sv.cmu.edu/css/css.pdf http://www.mandriva.com/security/advisories?name=MDVSA-2011:039 http://www.securityfocus.com/bid/38671 http://www.securitytracker.com/id?1023708 http://www.ubuntu.com/usn/USN-1006-1 http://www.vupen.com/english/advisories/2010/2722 http://www.vupen.com/english/advisories/2011/0212 http://www.vupen.com/english/advisories/2011/0552 https://exchange.xforce.ibmcloud.com/vulnerabilities/56837 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A7554
Share on: