CVE-2011-1290
Summary
| CVE | CVE-2011-1290 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-03-11 21:57:16 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS "style handling," nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Webkit | All | All | All | All |
| Hardware | Rim | Blackberry Torch 9800 | All | All | All | All |
| Application | Rim | Blackberry Torch 9800 Firmware | 6.0.0.246 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Chrome Nodesets Handling Integer Overflow Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Apple Safari Two Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| About the security content of Safari 5.0.5 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| About the security content of iOS 4.2.7 Software Update for iPhone | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| BlackBerry Device Software WebKit Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| APPLE-SA-2011-04-14-3 Safari 5.0.5 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Debian -- Security Information -- DSA-2192-1 chromium-browser | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| KB26132-Vulnerabilities in WebKit browser engine impact BlackBerry 6 | af854a3a-2127-422b-91ae-364da2661108 | www.blackberry.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Pwn2Own 2011: BlackBerry falls to WebKit browser attack | ZDNet | af854a3a-2127-422b-91ae-364da2661108 | www.zdnet.com | |
| APPLE-SA-2011-04-14-1 iOS 4.3.2 Software Update | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Blackberry Device Software Bug in WebKit Lets Remote Users Execute Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Apple iOS for iPhone 4 (CDMA) Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/71182 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Threat Intelligence | Digital Vaccine® | ThreatLinQ | Trend Micro | af854a3a-2127-422b-91ae-364da2661108 | dvlabs.tippingpoint.com | |
| Debian update for chromium-browser - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| WebKit Style Handling Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| APPLE-SA-2011-04-14-2 iOS 4.2.7 Software Update for iPhone | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Chrome Releases: Stable and Beta Channel Updates | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.