Security Advisory

CVE-2010-3796

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-11-16 21:00:00
Last updated 2024-09-16 17:18:33
Assigner apple
CVSS score not scored
State PUBLISHED

Description

Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.