CVE-2011-1290
WebKit - Remote Code Execution via CSS Style Handling Integer Overflow
Title source: llmDescription
Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS "style handling," nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.
References (25)
Core 25
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0654
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/44151
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/46849
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1025212
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4596
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/71182
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2192
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Apr/msg00002.html
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Apr/msg00001.html
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-11-104
Various Sources x_refsource_confirm
http://www.blackberry.com/btsc/KB26132
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0984
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0645
Various Sources x_refsource_misc
http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43782
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4607
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0671
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Apr/msg00000.html
Various Sources x_refsource_misc
http://www.zdnet.com/blog/security/pwn2own-2011-blackberry-falls-to-webkit-browser-attack/8401
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43748
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/517513/100/0/threaded
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/44154
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/66052
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43735
Scores
EPSS
0.0975
EPSS Percentile
95.0%
Details
CWE
CWE-189
Status
published
Products (3)
apple/webkit
rim/blackberry_torch_9800
rim/blackberry_torch_9800_firmware
6.0.0.246
Published
Mar 11, 2011
Tracked Since
Feb 18, 2026