{"api_version":"1","generated_at":"2026-07-24T22:37:32+00:00","cve":"CVE-2011-1290","urls":{"html":"https://cve.report/CVE-2011-1290","api":"https://cve.report/api/cve/CVE-2011-1290.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1290","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1290"},"summary":{"title":"CVE-2011-1290","description":"Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS \"style handling,\" nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-03-11 21:57:16","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/43748","name":"http://secunia.com/advisories/43748","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Google Chrome Nodesets Handling Integer Overflow Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/44151","name":"http://secunia.com/advisories/44151","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Apple Safari Two Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT4596","name":"http://support.apple.com/kb/HT4596","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of Safari 5.0.5","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/517513/100/0/threaded","name":"http://www.securityfocus.com/archive/1/517513/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-104","name":"http://www.zerodayinitiative.com/advisories/ZDI-11-104","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT4607","name":"http://support.apple.com/kb/HT4607","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of iOS 4.2.7 Software Update for iPhone","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43735","name":"http://secunia.com/advisories/43735","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BlackBerry Device Software WebKit Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0984","name":"http://www.vupen.com/english/advisories/2011/0984","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2011-04-14-3 Safari 5.0.5","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2011/dsa-2192","name":"http://www.debian.org/security/2011/dsa-2192","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-2192-1 chromium-browser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.blackberry.com/btsc/KB26132","name":"http://www.blackberry.com/btsc/KB26132","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"KB26132-Vulnerabilities in WebKit browser engine impact BlackBerry 6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66052","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66052","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zdnet.com/blog/security/pwn2own-2011-blackberry-falls-to-webkit-browser-attack/8401","name":"http://www.zdnet.com/blog/security/pwn2own-2011-blackberry-falls-to-webkit-browser-attack/8401","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Pwn2Own 2011: BlackBerry falls to WebKit browser attack | ZDNet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2011-04-14-1 iOS 4.3.2 Software Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0645","name":"http://www.vupen.com/english/advisories/2011/0645","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0671","name":"http://www.vupen.com/english/advisories/2011/0671","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1025212","name":"http://www.securitytracker.com/id?1025212","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Blackberry Device Software Bug in WebKit Lets Remote Users Execute Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/44154","name":"http://secunia.com/advisories/44154","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Apple iOS for iPhone 4 (CDMA) Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/71182","name":"http://osvdb.org/71182","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011","name":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Threat Intelligence | Digital Vaccine® | ThreatLinQ | Trend Micro","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43782","name":"http://secunia.com/advisories/43782","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Debian update for chromium-browser - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/46849","name":"http://www.securityfocus.com/bid/46849","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"WebKit Style Handling Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2011/0654","name":"http://www.vupen.com/english/advisories/2011/0654","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2011-04-14-2 iOS 4.2.7 Software Update for iPhone","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html","name":"http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Stable and Beta Channel Updates","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1290","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1290","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1290","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"webkit","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1290","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"rim","cpe5":"blackberry_torch_9800","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1290","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_torch_9800_firmware","cpe6":"6.0.0.246","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:21:34.187Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2011-0654","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0654"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html"},{"name":"44151","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/44151"},{"name":"46849","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/46849"},{"name":"1025212","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025212"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4596"},{"name":"71182","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/71182"},{"name":"DSA-2192","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2011/dsa-2192"},{"name":"APPLE-SA-2011-04-14-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00002.html"},{"name":"APPLE-SA-2011-04-14-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00001.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-104"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.blackberry.com/btsc/KB26132"},{"name":"ADV-2011-0984","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0984"},{"name":"ADV-2011-0645","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0645"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011"},{"name":"43782","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43782"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4607"},{"name":"ADV-2011-0671","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0671"},{"name":"APPLE-SA-2011-04-14-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00000.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zdnet.com/blog/security/pwn2own-2011-blackberry-falls-to-webkit-browser-attack/8401"},{"name":"43748","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43748"},{"name":"20110414 ZDI-11-104: (Pwn2Own) Webkit CSS Text Element Count Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/517513/100/0/threaded"},{"name":"44154","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/44154"},{"name":"google-webkit-style-code-execution(66052)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66052"},{"name":"43735","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43735"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-03-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS \"style handling,\" nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2011-0654","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0654"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html"},{"name":"44151","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/44151"},{"name":"46849","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/46849"},{"name":"1025212","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025212"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4596"},{"name":"71182","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/71182"},{"name":"DSA-2192","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2011/dsa-2192"},{"name":"APPLE-SA-2011-04-14-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00002.html"},{"name":"APPLE-SA-2011-04-14-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00001.html"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-104"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.blackberry.com/btsc/KB26132"},{"name":"ADV-2011-0984","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0984"},{"name":"ADV-2011-0645","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0645"},{"tags":["x_refsource_MISC"],"url":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011"},{"name":"43782","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43782"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4607"},{"name":"ADV-2011-0671","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0671"},{"name":"APPLE-SA-2011-04-14-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00000.html"},{"tags":["x_refsource_MISC"],"url":"http://www.zdnet.com/blog/security/pwn2own-2011-blackberry-falls-to-webkit-browser-attack/8401"},{"name":"43748","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43748"},{"name":"20110414 ZDI-11-104: (Pwn2Own) Webkit CSS Text Element Count Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/517513/100/0/threaded"},{"name":"44154","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/44154"},{"name":"google-webkit-style-code-execution(66052)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66052"},{"name":"43735","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43735"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-1290","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS \"style handling,\" nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2011-0654","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0654"},{"name":"http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html"},{"name":"44151","refsource":"SECUNIA","url":"http://secunia.com/advisories/44151"},{"name":"46849","refsource":"BID","url":"http://www.securityfocus.com/bid/46849"},{"name":"1025212","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025212"},{"name":"http://support.apple.com/kb/HT4596","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT4596"},{"name":"71182","refsource":"OSVDB","url":"http://osvdb.org/71182"},{"name":"DSA-2192","refsource":"DEBIAN","url":"http://www.debian.org/security/2011/dsa-2192"},{"name":"APPLE-SA-2011-04-14-3","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00002.html"},{"name":"APPLE-SA-2011-04-14-2","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00001.html"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-11-104","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-11-104"},{"name":"http://www.blackberry.com/btsc/KB26132","refsource":"CONFIRM","url":"http://www.blackberry.com/btsc/KB26132"},{"name":"ADV-2011-0984","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0984"},{"name":"ADV-2011-0645","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0645"},{"name":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011","refsource":"MISC","url":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011"},{"name":"43782","refsource":"SECUNIA","url":"http://secunia.com/advisories/43782"},{"name":"http://support.apple.com/kb/HT4607","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT4607"},{"name":"ADV-2011-0671","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0671"},{"name":"APPLE-SA-2011-04-14-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2011//Apr/msg00000.html"},{"name":"http://www.zdnet.com/blog/security/pwn2own-2011-blackberry-falls-to-webkit-browser-attack/8401","refsource":"MISC","url":"http://www.zdnet.com/blog/security/pwn2own-2011-blackberry-falls-to-webkit-browser-attack/8401"},{"name":"43748","refsource":"SECUNIA","url":"http://secunia.com/advisories/43748"},{"name":"20110414 ZDI-11-104: (Pwn2Own) Webkit CSS Text Element Count Remote Code Execution Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/517513/100/0/threaded"},{"name":"44154","refsource":"SECUNIA","url":"http://secunia.com/advisories/44154"},{"name":"google-webkit-style-code-execution(66052)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66052"},{"name":"43735","refsource":"SECUNIA","url":"http://secunia.com/advisories/43735"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-1290","datePublished":"2011-03-11T21:00:00.000Z","dateReserved":"2011-03-06T00:00:00.000Z","dateUpdated":"2024-08-06T22:21:34.187Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-03-11 21:57:16","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*","matchCriteriaId":"461EFB63-7933-488C-BB4E-7C913364F5A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_torch_9800_firmware:6.0.0.246:*:*:*:*:*:*:*","matchCriteriaId":"C295C9D4-54E7-44C8-98B6-8E0588D8FAA0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:rim:blackberry_torch_9800:*:*:*:*:*:*:*:*","matchCriteriaId":"BE6974E3-F348-4C8C-B199-4E680D6CB0E7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1290","Ordinal":"1","Title":"CVE-2011-1290","CVE":"CVE-2011-1290","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1290","Ordinal":"1","NoteData":"Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS \"style handling,\" nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.","Type":"Description","Title":"CVE-2011-1290"},{"CveYear":"2011","CveId":"1290","Ordinal":"2","NoteData":"2011-03-11","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1290","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}