CVE-2011-1290 describes an integer overflow vulnerability in WebKit, affecting products like Google Chrome before version 10.0.648.133, Apple Safari before 5.0.5, and the RIM BlackBerry Torch 9800. This flaw, related to CSS style handling, nodesets, and length values, allows remote attackers to execute arbitrary code. With a CVSS score of 10.0, it represents a critical risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While demonstrated at a Pwn2Own competition, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:* | ||
6.0.0.246CPE matchmatch criteria | cpe:2.3:a:rim:blackberry_torch_9800_firmware:6.0.0.246:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:rim:blackberry_torch_9800:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.