CVE Vulnerabilities

CVE-2010-1760

Published: Aug 19, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.

Affected Software

NameVendorStart VersionEnd Version
WebkitApple*r58408 (including)
WebkitAppler50173 (including)r50173 (including)
WebkitAppler56187 (including)r56187 (including)
WebkitAppler56188 (including)r56188 (including)
WebkitAppler56379 (including)r56379 (including)
Chromium-browserUbuntudevel*
Chromium-browserUbuntulucid*
Chromium-browserUbuntumaverick*
Chromium-browserUbuntunatty*
Chromium-browserUbuntuoneiric*
Qt4-x11Ubuntujaunty*
Qt4-x11Ubuntukarmic*
Qt4-x11Ubuntulucid*
WebkitUbuntuhardy*
WebkitUbuntujaunty*
WebkitUbuntukarmic*
WebkitUbuntulucid*
WebkitUbuntuupstream*

References