ID: CVE-2010-0044

Last Modified: Sept. 19, 2017

PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.

Access Vector: Network

Access Complexity: Medium

Authentication: None

Confidentiality Impact: Partial

Integrity Impact: None

Availability Impact: None

Base Score: 4.3

Exploitability Score: 8.6

Impact Score: 2.9

CVSS V2: AV:N/AC:M/Au:N/C:P/I:N/A:N

Specialize CVSS-Score

CWE-16

Condition Configuration
OR
OR
Alle Schwachstellen für apple
Alle Schwachstellen für apple
Alle Schwachstellen für apple
Alle Schwachstellen für apple
Alle Schwachstellen für apple
Alle Schwachstellen für apple
                    <?xml version="1.0" ?>
<set operator="and">
    <set operator="or">
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0.3:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:*"/>
    </set>
    <prop key="program_influence" value="input"/>
    <prop key="range" value="remote"/>
</set>

                  
                      <?xml version="1.0" ?>
<set operator="and">
    <set operator="or">
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0.3:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:*"/>
        <prop key="application" value="cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:*"/>
    </set>
    <prop key="program_influence" value="input"/>
    <prop key="data" value="any"/>
    <prop key="data_influence" value="read"/>
    <prop key="range" value="remote"/>
</set>