← All CVEs

CVE-2010-5071

medium · 5

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

5
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2011-12-07
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
microsoftie7.0.6000.16711
microsoftie8.0.7600.16385
microsoftie8.0b
microsoftinternet_explorer<= 8
microsoftinternet_explorer3.0
microsoftinternet_explorer3.0.1
microsoftinternet_explorer3.0.2
microsoftinternet_explorer3.1
microsoftinternet_explorer3.2
microsoftinternet_explorer4.0
microsoftinternet_explorer4.0.1
microsoftinternet_explorer4.0.1
microsoftinternet_explorer4.0.1
microsoftinternet_explorer4.01
microsoftinternet_explorer4.1
microsoftinternet_explorer4.01
microsoftinternet_explorer4.5
microsoftinternet_explorer4.40.308
microsoftinternet_explorer4.40.520
microsoftinternet_explorer4.70.1155
microsoftinternet_explorer4.70.1158
microsoftinternet_explorer4.70.1215
microsoftinternet_explorer4.70.1300
microsoftinternet_explorer4.71.544
microsoftinternet_explorer4.71.1008.3
microsoftinternet_explorer4.71.1712.6
microsoftinternet_explorer4.72.2106.8
microsoftinternet_explorer4.72.3110.8
microsoftinternet_explorer4.72.3612.1713
microsoftinternet_explorer5
microsoftinternet_explorer5.0
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.00.0518.10
microsoftinternet_explorer5.00.0910.1309
microsoftinternet_explorer5.00.2014.0216
microsoftinternet_explorer5.00.2314.1003

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-5071