« Back to list

CVE-2010-5070

Status: ModifiedMedium (5)—

The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different vulnerability than CVE-2010-2264. NOTE: this may overlap CVE-2010-5073.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2010-5070",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-12-07T19:55:01.423",
  "references": [
    {
      "url": "http://w2spconf.com/2010/papers/p26.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://w2spconf.com/2010/papers/p26.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different vulnerability than CVE-2010-2264.  NOTE: this may overlap CVE-2010-5073."
    },
    {
      "lang": "es",
      "value": "La ejecución de JavaScript en Apple Safari v4, no restringe adecuadamente el conjunto de valores contenidos en el objeto devuelto por el método getComputedStyle, lo que permite a atacantes remotos obtener información sensible acerca de las páginas web visitadas por llamar a este método. Una vulnerabilidad diferente de CVE-2010-2264. Esto puede solaparse con CVE-2010-5073."
    }
  ],
  "lastModified": "2026-06-16T23:26:04.840",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9BDA6DB4-A0DA-43CA-AABD-10EEEEB28EAB"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.0:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DC87F61-3463-468A-BF0B-070816BBC3CA"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02EAC196-AE43-4787-9AF9-E79E2E1BBA46"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2FD40E4-D4C9-492E-8432-ABC9BD2C7E67"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36EA71E0-63F7-46FF-AF11-792741F27628"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80E36485-565D-4FAA-A6AD-57DF42D47462"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73E9C17F-C99E-4ABB-B312-31F87BC0C0E8"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46D8318A-9383-42A7-9A6A-2EB2736338B7"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79DC6C51-CEEA-4CBF-87D2-8007B7C3D67F"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7B6AD89-D60C-4C8F-A9E6-4380A6B8DB13"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2451165-7831-426E-BA07-B3A57F3589C5"
            },
            {
              "criteria": "cpe:2.3:a:apple:safari:4.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "211A142A-CB1E-48DC-AEA1-096F3E750063"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}