CVE Vulnerabilities

CVE-2010-1760

Published: Aug 19, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.

Affected Software

Name Vendor Start Version End Version
Webkit Apple * r58408 (including)
Webkit Apple r50173 (including) r50173 (including)
Webkit Apple r56187 (including) r56187 (including)
Webkit Apple r56188 (including) r56188 (including)
Webkit Apple r56379 (including) r56379 (including)
Chromium-browser Ubuntu devel *
Chromium-browser Ubuntu lucid *
Chromium-browser Ubuntu maverick *
Chromium-browser Ubuntu natty *
Chromium-browser Ubuntu oneiric *
Qt4-x11 Ubuntu jaunty *
Qt4-x11 Ubuntu karmic *
Qt4-x11 Ubuntu lucid *
Webkit Ubuntu hardy *
Webkit Ubuntu jaunty *
Webkit Ubuntu karmic *
Webkit Ubuntu lucid *
Webkit Ubuntu upstream *

References