CVE-2011-1290

WebKit - Remote Code Execution via CSS Style Handling Integer Overflow

Title source: llm
STIX 2.1

Description

Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS "style handling," nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.

References (25)

Core 25
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0654
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44151
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46849
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025212
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4596
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/71182
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2192
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Apr/msg00002.html
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Apr/msg00001.html
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-11-104
Various Sources x_refsource_confirm
http://www.blackberry.com/btsc/KB26132
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0984
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0645
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43782
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4607
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0671
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Apr/msg00000.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43748
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/517513/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44154
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/66052
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43735

Scores

EPSS 0.0975
EPSS Percentile 95.0%

Details

CWE
CWE-189
Status published
Products (3)
apple/webkit
rim/blackberry_torch_9800
rim/blackberry_torch_9800_firmware 6.0.0.246
Published Mar 11, 2011
Tracked Since Feb 18, 2026