CVE-2010-1386

WebKit <r56188-1.2.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.

References (12)

Core 12
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
Third Party Advisory x_refsource_confirm
http://security-tracker.debian.org/tracker/CVE-2010-1386
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2722
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43068
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1006-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41856
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0212
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/42500
Various Sources x_refsource_confirm
http://trac.webkit.org/changeset/56188
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0552
Various Sources x_refsource_confirm
https://bugs.webkit.org/show_bug.cgi?id=36255

Scores

EPSS 0.0213
EPSS Percentile 80.1%

Details

CWE
CWE-264
Status published
Products (2)
apple/webkit r50173
apple/webkit < r56187
Published Aug 19, 2010
Tracked Since Feb 18, 2026