The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input fields.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11112 | vdb entry signature |
http://support.apple.com/kb/HT4276 | vendor advisory |
http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html | patch vendor advisory |
http://www.securityfocus.com/bid/42020 | vdb entry patch |