CVE-2010-1760: loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementati ...

Severity: Critical

CVSS Score: 10

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.