CVE-2010-0044

MEDIUM

Description

PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.

References

http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

http://osvdb.org/62937

http://support.apple.com/kb/HT4070

http://www.securityfocus.com/bid/38671

http://www.securityfocus.com/bid/38675

https://exchange.xforce.ibmcloud.com/vulnerabilities/56830

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7051

Details

Source: MITRE

Published: 2010-03-15

Updated: 2017-09-19

Type: CWE-16

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM