CVE-2010-5070

Apple Safari 4 - Information Disclosure via getComputedStyle Method

Title source: llm
STIX 2.1

Description

The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different vulnerability than CVE-2010-2264. NOTE: this may overlap CVE-2010-5073.

References (1)

Core 1
Core References
Exploit x_refsource_misc
http://w2spconf.com/2010/papers/p26.pdf

Scores

EPSS 0.0164
EPSS Percentile 73.9%

Details

CWE
CWE-264
Status published
Products (11)
apple/safari 4.0 (2 CPE variants)
apple/safari 4.0.0b
apple/safari 4.0.1
apple/safari 4.0.2
apple/safari 4.0.3
apple/safari 4.0.4
apple/safari 4.0.5
apple/safari 4.1
apple/safari 4.1.1
apple/safari 4.1.2
... and 1 more
Published Dec 07, 2011
Tracked Since Feb 18, 2026