CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
Percentile
76.5%
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not
properly handle the Attr.style accessor, which allows remote attackers to
bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token
sequences via a crafted web site.
Author | Note |
---|---|
jdstrand | qt4-x11 unmaintained upstream (see README.webkit for details) |