Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple WebKit download样式表敏感信息泄露漏洞
Vulnerability Description
WebKit 是一个开源浏览器网页排版引擎,与之相应的引擎有Gecko(Mozilla,Firefox 等使用的排版引擎)和Trident(也称为MSHTML,IE 使用的排版引擎)。 Google Chrome 4.0.249.78和Apple Safari 4.0.5版本中使用的WebKit r52784之前版本的download样式表中存在敏感信息泄露漏洞。当download样式MIME类型不正确和document样式畸形时,允许跨源加载CSS样式。远程攻击者可借助特制文件获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A