First published: Wed Dec 07 2011(Updated: )
The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =7.0.6000.16711 | |
Microsoft Internet Explorer | =8.0.7600.16385 | |
Microsoft Internet Explorer | =8.0b | |
Internet Explorer | <=8 | |
Internet Explorer | =3.0 | |
Internet Explorer | =3.0.1 | |
Internet Explorer | =3.0.2 | |
Internet Explorer | =3.1 | |
Internet Explorer | =3.2 | |
Internet Explorer | =4.0 | |
Internet Explorer | =4.0.1 | |
Internet Explorer | =4.0.1-sp1 | |
Internet Explorer | =4.0.1-sp2 | |
Internet Explorer | =4.01 | |
Internet Explorer | =4.1 | |
Internet Explorer | =4.01-sp1 | |
Internet Explorer | =4.5 | |
Internet Explorer | =4.40.308 | |
Internet Explorer | =4.40.520 | |
Internet Explorer | =4.70.1155 | |
Internet Explorer | =4.70.1158 | |
Internet Explorer | =4.70.1215 | |
Internet Explorer | =4.70.1300 | |
Internet Explorer | =4.71.544 | |
Internet Explorer | =4.71.1008.3 | |
Internet Explorer | =4.71.1712.6 | |
Internet Explorer | =4.72.2106.8 | |
Internet Explorer | =4.72.3110.8 | |
Internet Explorer | =4.72.3612.1713 | |
Internet Explorer | =5 | |
Internet Explorer | =5.0 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp3 | |
Internet Explorer | =5.0.1-sp4 | |
Internet Explorer | =5.00.0518.10 | |
Internet Explorer | =5.00.0910.1309 | |
Internet Explorer | =5.00.2014.0216 | |
Internet Explorer | =5.00.2314.1003 | |
Internet Explorer | =5.00.2516.1900 | |
Internet Explorer | =5.00.2614.3500 | |
Internet Explorer | =5.00.2919.800 | |
Internet Explorer | =5.00.2919.3800 | |
Internet Explorer | =5.00.2919.6307 | |
Internet Explorer | =5.00.2920.0000 | |
Internet Explorer | =5.00.3103.1000 | |
Internet Explorer | =5.00.3105.0106 | |
Internet Explorer | =5.00.3314.2101 | |
Internet Explorer | =5.00.3315.1000 | |
Internet Explorer | =5.00.3502.1000 | |
Internet Explorer | =5.00.3700.1000 | |
Internet Explorer | =5.01 | |
Internet Explorer | =5.1 | |
Internet Explorer | =5.01-sp1 | |
Internet Explorer | =5.01-sp2 | |
Internet Explorer | =5.01-sp3 | |
Internet Explorer | =5.01-sp4 | |
Internet Explorer | =5.2.3 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-preview | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.50.3825.1300 | |
Internet Explorer | =5.50.4030.2400 | |
Internet Explorer | =5.50.4134.0100 | |
Internet Explorer | =5.50.4134.0600 | |
Internet Explorer | =5.50.4308.2900 | |
Internet Explorer | =5.50.4522.1800 | |
Internet Explorer | =5.50.4807.2300 | |
Internet Explorer | =6 | |
Internet Explorer | =6-sp1 | |
Internet Explorer | =6.0 | |
Internet Explorer | =6.00.2462.0000 | |
Internet Explorer | =6.00.2479.0006 | |
Internet Explorer | =6.0.2600 | |
Internet Explorer | =6.00.2600.0000 | |
Internet Explorer | =6.0.2800 | |
Internet Explorer | =6.0.2800.1106 | |
Internet Explorer | =6.00.2800.1106 | |
Internet Explorer | =6.0.2900 | |
Internet Explorer | =6.0.2900.2180 | |
Internet Explorer | =6.00.2900.2180 | |
Internet Explorer | =6.00.3663.0000 | |
Internet Explorer | =6.00.3718.0000 | |
Internet Explorer | =6.00.3790.0000 | |
Internet Explorer | =6.00.3790.1830 | |
Internet Explorer | =6.00.3790.3959 | |
Internet Explorer | =7 | |
Internet Explorer | =7.0 | |
Internet Explorer | =7.0-beta | |
Internet Explorer | =7.0-beta1 | |
Internet Explorer | =7.0-beta2 | |
Internet Explorer | =7.0-beta3 | |
Internet Explorer | =7.0.5730-unknown | |
Internet Explorer | =7.0.5730.11 | |
Internet Explorer | =7.00.5730.1100 | |
Internet Explorer | =7.00.6000.16386 | |
Internet Explorer | =7.00.6000.16441 | |
Internet Explorer | =8.0.6001 | |
Internet Explorer | =8.0.6001-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-5071 is classified as a moderate severity vulnerability.
To mitigate CVE-2010-5071, upgrade to a version of Internet Explorer that is not affected by this vulnerability.
CVE-2010-5071 affects Internet Explorer versions 8.0 and earlier, including version 7.0.
CVE-2010-5071 can be exploited by remote attackers to gain unauthorized access to sensitive information about visited web pages.
Microsoft has released updates addressing CVE-2010-5071, which can be applied to affected Internet Explorer versions.