CVE-2010-2264
published 2010-06-11CVE-2010-2264: The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.60%
83.8th percentile
The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document.
Affected
456 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0.5 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mf5v-3c9h-j7h3: The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-5070 [MEDIUM] GHSA-mf5v-3c9h-j7h3: The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle
The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different vulnerability than CVE-2010-2264. NOTE: this may overlap CVE-2010-5073.
GHSA
GHSA-vfgv-7h5p-hhgc: The Cascading Style Sheets (CSS) implementation in Opera 10
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-5068 [MEDIUM] CWE-200 GHSA-vfgv-7h5p-hhgc: The Cascading Style Sheets (CSS) implementation in Opera 10
The Cascading Style Sheets (CSS) implementation in Opera 10.5 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
GHSA
GHSA-ccqg-4ff6-jg4g: The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers t
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-5069 [MEDIUM] CWE-200 GHSA-ccqg-4ff6-jg4g: The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers t
The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE: this may overlap CVE-2010-2264.
GHSA
GHSA-g62r-fg2h-rgg7: The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-17
CVE-2010-2264 [MEDIUM] CWE-200 GHSA-g62r-fg2h-rgg7: The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5
The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document.
GHSA
GHSA-fxv5-cqrh-qvhc: The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8
ghsa_unreviewed·2022-04-30·CVSS 4.3
CVE-2002-2435 [MEDIUM] CWE-200 GHSA-fxv5-cqrh-qvhc: The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8
The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
GHSA
GHSA-j5hm-v5hc-jgjr: The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4
ghsa_unreviewed·2022-04-30·CVSS 4.3
CVE-2002-2436 [MEDIUM] CWE-200 GHSA-j5hm-v5hc-jgjr: The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40105http://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1024067http://support.apple.com/kb/HT4196http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/40620http://www.securityfocus.com/bid/40756http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/1373http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40105http://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1024067http://support.apple.com/kb/HT4196http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/40620http://www.securityfocus.com/bid/40756http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/1373http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552
2010-06-11
Published