Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-3259

Опубликовано: 07 сент. 2010
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6.0.472.53~r57914-0ubuntu1
hardy

DNE

jaunty

DNE

karmic

DNE

lucid

released

6.0.472.53~r57914-0ubuntu0.10.04.1
maverick

not-affected

6.0.472.53~r57914-0ubuntu1
natty

not-affected

6.0.472.53~r57914-0ubuntu1
oneiric

not-affected

6.0.472.53~r57914-0ubuntu1
upstream

released

6.0.472.53

Показывать по

РелизСтатусПримечание
dapper

not-affected

no webkit
devel

not-affected

webkit isn't built
hardy

not-affected

no webkit
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

not-affected

webkit isn't built
natty

not-affected

webkit isn't built
oneiric

not-affected

webkit isn't built
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.2.5-0ubuntu2
hardy

ignored

end of life
jaunty

ignored

end of life
karmic

released

1.2.5-0ubuntu0.9.10.1
lucid

released

1.2.5-0ubuntu0.10.04.1
maverick

released

1.2.5-0ubuntu0.10.10.1
natty

not-affected

1.2.5-0ubuntu2
oneiric

not-affected

1.2.5-0ubuntu2
upstream

released

1.2.5

Показывать по

EPSS

Процентиль: 73%
0.00823
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 15 лет назад

WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.

nvd
почти 15 лет назад

WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.

debian
почти 15 лет назад

WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, G ...

github
около 3 лет назад

WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.

oracle-oval
больше 14 лет назад

ELSA-2011-0177: webkitgtk security update (MODERATE)

EPSS

Процентиль: 73%
0.00823
Низкий

4.3 Medium

CVSS2