CVE Vulnerabilities

CVE-2010-1386

Published: Aug 19, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.

Affected Software

NameVendorStart VersionEnd Version
WebkitApple*r56187 (including)
WebkitAppler50173 (including)r50173 (including)
Chromium-browserUbuntudevel*
Chromium-browserUbuntulucid*
Chromium-browserUbuntumaverick*
Chromium-browserUbuntunatty*
Chromium-browserUbuntuoneiric*
Qt4-x11Ubuntujaunty*
Qt4-x11Ubuntukarmic*
Qt4-x11Ubuntulucid*
WebkitUbuntuhardy*
WebkitUbuntujaunty*
WebkitUbuntukarmic*
WebkitUbuntulucid*
WebkitUbuntuupstream*

References