CVE-2010-0651
published 2010-02-18CVE-2010-0651: WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.75%
75.3th percentile
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0.4 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | webkit | <= r53524 | — |
| chrome | <= 4.0.249.78 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 2.0.172.32 information disclosure (ID 52784 / Nessus ID 44317)
vuldb·2026-04-30·CVSS 4.3
CVE-2010-0651 [MEDIUM] Google Chrome up to 2.0.172.32 information disclosure (ID 52784 / Nessus ID 44317)
A vulnerability was found in Google Chrome up to 2.0.172.32. It has been rated as problematic. Affected by this issue is some unknown functionality. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2010-0651. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
GHSA-9j9x-qw8r-p5pq: WebKit in Apple Safari before 4
ghsa_unreviewed·2022-05-02·CVSS 4.3
CVE-2010-0051 [MEDIUM] CWE-20 GHSA-9j9x-qw8r-p5pq: WebKit in Apple Safari before 4
WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document. NOTE: this might overlap CVE-2010-0651.
GHSA
GHSA-vffh-48qx-8xgf: WebKit before r52784, as used in Google Chrome before 4
ghsa_unreviewed·2022-05-02
CVE-2010-0651 [MEDIUM] CWE-200 GHSA-vffh-48qx-8xgf: WebKit before r52784, as used in Google Chrome before 4
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
Red Hat
webkit: remote information disclosure
vendor_redhat·2009-01-26·CVSS 4.3
CVE-2010-0051 [MEDIUM] webkit: remote information disclosure
webkit: remote information disclosure
WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document. NOTE: this might overlap CVE-2010-0651.
Red Hat
webkit: remote information disclosure
vendor_redhat·2009-01-26·CVSS 4.3
CVE-2010-0651 [MEDIUM] webkit: remote information disclosure
webkit: remote information disclosure
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2794 spice-xpi symlink attack
bugzilla·2010-08-02·CVSS 3.3
CVE-2010-2794 [LOW] CVE-2010-2794 spice-xpi symlink attack
CVE-2010-2794 spice-xpi symlink attack
Spice-xpi uses predictable name for it's log file which a malicious user could use to overwrite arbitrary files via a symlink attack, with the privileges of the user running spice-xpi.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0651 https://rhn.redhat.com/errata/RHSA-2010-0651.html
Bugzilla
CVE-2010-2792 spice-xpi/qspice-client unix socket race
bugzilla·2010-08-02·CVSS 3.3
CVE-2010-2792 [LOW] CVE-2010-2792 spice-xpi/qspice-client unix socket race
CVE-2010-2792 spice-xpi/qspice-client unix socket race
There is a race in spice-xpi when a local attacker is able to create a unix socket with the expected name that is used for parameter passing (password, cert file) between spice-xpi and spice client.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0632 https://rhn.redhat.com/errata/RHSA-2010-0632.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0651 https://rhn.redhat.com/errata/RHSA-2010-0651.html
Bugzilla
CVE-2010-0046, CVE-2010-0047, CVE-2010-0048, CVE-2010-0049, CVE-2010-0050, CVE-2010-0052, CVE-2010-0053, CVE-2010-0054 qt, webkitgtk: multiple security vulnerabilities in WebKit
bugzilla·2010-03-03·CVSS 9.3
CVE-2010-0046 [CRITICAL] CVE-2010-0046, CVE-2010-0047, CVE-2010-0048, CVE-2010-0049, CVE-2010-0050, CVE-2010-0052, CVE-2010-0053, CVE-2010-0054 qt, webkitgtk: multiple security vulnerabilities in WebKit
CVE-2010-0046, CVE-2010-0047, CVE-2010-0048, CVE-2010-0049, CVE-2010-0050, CVE-2010-0052, CVE-2010-0053, CVE-2010-0054 qt, webkitgtk: multiple security vulnerabilities in WebKit
A number of security vulnerabilities were reported in WebKit:
CVE-2010-0046: CSS format() argument memory corruption
https://bugs.webkit.org/show_bug.cgi?id=31815
http://trac.webkit.org/changeset/51727
CSS format() arguments were always treated as strings, which could result
in a crash or arbitrary code execution if an integer or other unexpected
type was used instead.
CVE-2010-0047: Call-after-free in HTMLObjectElement::renderFallBackContent (ZDI-CAN-579)
https://bugs.webkit.org/show_bug.cgi?id=31277
http://trac.webkit.org/changeset/50698
Changes to the style of an OBJECT element resulted in the creation of
Bugzilla
CVE-2010-0654 firefox: cross-domain information disclosure
bugzilla·2010-02-25·CVSS 4.3
CVE-2010-0654 [MEDIUM] CVE-2010-0654 firefox: cross-domain information disclosure
CVE-2010-0654 firefox: cross-domain information disclosure
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0654 to
the following vulnerability:
Mozilla Firefox permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document.
http://code.google.com/p/chromium/issues/detail?id=9877
The above CVE description is a bit misleading. They mention Firefox, but point to a Google Chrome bug report. This issue affects Gecko-based browsers as well as WebKit-based browsers, with a more detailed writeup written by Chris Evans:
http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domai
Bugzilla
CVE-2010-0651 webkit: remote information disclosure
bugzilla·2010-02-24·CVSS 4.3
CVE-2010-0651 [MEDIUM] CVE-2010-0651 webkit: remote information disclosure
CVE-2010-0651 webkit: remote information disclosure
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0651 to
the following vulnerability:
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document.
http://code.google.com/p/chromium/issues/detail?id=9877
http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html
http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs
http://trac.webkit.org/changeset/52784
https://bugs.webkit.org/show_bug.cgi?id=29820
http://
http://code.google.com/p/chromium/issues/detail?id=9877http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://trac.webkit.org/changeset/52784http://websec.sv.cmu.edu/css/css.pdfhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=29820https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13653http://code.google.com/p/chromium/issues/detail?id=9877http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1023506http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugshttp://trac.webkit.org/changeset/52784http://websec.sv.cmu.edu/css/css.pdfhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=29820https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13653
2010-02-18
Published