Unrated severityNVD Advisory· Published Aug 19, 2010· Updated Jun 16, 2026
CVE-2010-1760
CVE-2010-1760
Description
loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*range: <=r58408
- cpe:2.3:a:apple:webkit:r50173:*:*:*:*:*:*:*
- cpe:2.3:a:apple:webkit:r56187:*:*:*:*:*:*:*
- cpe:2.3:a:apple:webkit:r56188:*:*:*:*:*:*:*
- cpe:2.3:a:apple:webkit:r56379:*:*:*:*:*:*:*
- Range: < r58409
Patches
Vulnerability mechanics
References
12- lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlnvd
- secunia.com/advisories/41856nvd
- secunia.com/advisories/43068nvd
- security-tracker.debian.org/tracker/CVE-2010-1760nvd
- trac.webkit.org/changeset/58409nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/42494nvd
- www.ubuntu.com/usn/USN-1006-1nvd
- www.vupen.com/english/advisories/2010/2722nvd
- www.vupen.com/english/advisories/2011/0212nvd
- www.vupen.com/english/advisories/2011/0552nvd
- bugs.webkit.org/show_bug.cginvd
News mentions
0No linked articles in our index yet.