PT-2010-3431 · Apple · Safari+1
Jeremiah Grossman
·
Published
2010-07-30
·
Updated
2017-09-19
·
CVE-2010-1796
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Safari versions prior to 5.0.1 on Mac OS X 10.5 through 10.6 and Windows
Safari versions prior to 4.1.1 on Mac OS X 10.4
Description
The issue allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input fields. This is related to the AutoFill feature.
Recommendations
For Safari versions prior to 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, update to version 5.0.1 or later.
For Safari versions prior to 4.1.1 on Mac OS X 10.4, update to version 4.1.1 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Macos X
Safari