CVE-2010-5072

The JavaScript implementation in Opera 10.5 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opera:opera_browser:10.50:*:*:*:*:*:*:*

History

21 Nov 2024, 01:22

Type Values Removed Values Added
References () http://w2spconf.com/2010/papers/p26.pdf - Exploit () http://w2spconf.com/2010/papers/p26.pdf - Exploit

Information

Published : 2011-12-07 19:55

Updated : 2024-11-21 01:22


NVD link : CVE-2010-5072

Mitre link : CVE-2010-5072

CVE.ORG link : CVE-2010-5072


JSON object : View

Products Affected

opera

  • opera_browser
CWE
CWE-264

Permissions, Privileges, and Access Controls