CVE-2010-1796: Infoleak
The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input fields.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1796?
CVE-2010-1796 is considered a moderate severity vulnerability that allows exposure of sensitive information.
How do I fix CVE-2010-1796?
To fix CVE-2010-1796, you need to update Apple Safari to version 5.0.1 or later.
What types of systems are affected by CVE-2010-1796?
CVE-2010-1796 affects Apple Safari versions prior to 5.0.1 on Mac OS X 10.5 to 10.6 and Windows platforms.
Is CVE-2010-1796 still exploitable?
CVE-2010-1796 is no longer exploitable on systems that have been updated to the patched versions of Safari.
What information can be compromised due to CVE-2010-1796?
CVE-2010-1796 can allow attackers to obtain sensitive Address Book Card information.