CVE-2010-3804
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to CVE-2008-5913 and CVE-2010-3171.
- Apple Safari
- ≤ 5.0.2, 5.0, 5.0.1
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 9.1% (95th percentile)
- Weakness
- CWE-310
- NVD status
- Modified
- Published
- 2010-11-20
CVE-2010-3804 at NVD
2 known exploits for CVE-2010-3804
Proof-of-concept code and exploit modules indexed by Sploitus