CVE-2010-0044

Apple Safari <4.0.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38675
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56830
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4070
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/62937
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7051
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38671

Scores

EPSS 0.0153
EPSS Percentile 72.2%

Details

CWE
CWE-16
Status published
Products (6)
apple/safari 4.0
apple/safari 4.0.0b
apple/safari 4.0.1
apple/safari 4.0.2
apple/safari 4.0.3
apple/safari < 4.0.4
Published Mar 15, 2010
Tracked Since Feb 18, 2026