CVE-2010-0656Sensitive Information Exposure in Apple Webkit

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 30.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 18
Latest updateMay 2

Description

WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDgoogle/chrome4.0.249.78+47
NVDapple/webkitr51280

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g5q4-36jf-94r5: WebKit before r51295, as used in Google Chrome before 42022-05-02
CVEList
CVE-2010-0656: WebKit before r51295, as used in Google Chrome before 42010-02-18

📋Vendor Advisories

1
Red Hat
webkit: possible information disclosure via xhr for file:/// URLs2009-08-27

💬Community

1
Bugzilla
CVE-2010-0656 webkit: possible information disclosure via xhr for file:/// URLs2010-02-24
CVE-2010-0656 — Sensitive Information Exposure in Apple | cvebase