PT-2010-5083 · Apple · Safari

Jason Hullinger

·

Published

2010-11-16

·

Updated

2010-11-17

·

CVE-2010-3796

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Safari versions prior to 10.6.5 in Mac OS X 10.5.8 and 10.6.x
Description The issue allows remote attackers to obtain sensitive information by using a feed: URL containing a Java applet that performs DOM modifications, as Safari does not block Java applets in an RSS feed.
Recommendations For Safari in Mac OS X 10.5.8 and 10.6.x before 10.6.5, consider disabling Java applets in RSS feeds until a patch is available. Restrict access to RSS feeds that may contain malicious Java applets to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3796

Affected Products

Safari