Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-1290

34
FAUCET Score

CVE-2011-1290 describes an integer overflow vulnerability in WebKit, affecting products like Google Chrome before version 10.0.648.133, Apple Safari before 5.0.5, and the RIM BlackBerry Torch 9800. This flaw, related to CSS style handling, nodesets, and length values, allows remote attackers to execute arbitrary code. With a CVSS score of 10.0, it represents a critical risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While demonstrated at a Pwn2Own competition, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*
6.0.0.246CPE matchmatch criteria
cpe:2.3:a:rim:blackberry_torch_9800_firmware:6.0.0.246:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:h:rim:blackberry_torch_9800:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
9.75%
Probability of exploitation in next 30 days
EPSS Percentile
95.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0975 is in the 92nd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

dvlabs.tippingpoint.com / blog/2011/02/02/pwn2own-2011
googlechromereleases.blogspot.com / 2011/03/stable-and-beta-channel-updates.html
lists.apple.com / archives/security-announce/2011//Apr/msg00000.html
lists.apple.com / archives/security-announce/2011//Apr/msg00001.html
lists.apple.com / archives/security-announce/2011//Apr/msg00002.html
osvdb.org / 71182
secunia.com / advisories/43735
Vendor Advisory
secunia.com / advisories/43748
Vendor Advisory
secunia.com / advisories/43782
Vendor Advisory
secunia.com / advisories/44151
Vendor Advisory
secunia.com / advisories/44154
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/66052
support.apple.com / kb/HT4596
support.apple.com / kb/HT4607
blackberry.com / btsc/KB26132
debian.org / security/2011/dsa-2192
securityfocus.com / archive/1/517513/100/0/threaded
securityfocus.com / bid/46849
securitytracker.com / id
vupen.com / english/advisories/2011/0645
Vendor Advisory
vupen.com / english/advisories/2011/0654
Vendor Advisory
vupen.com / english/advisories/2011/0671
vupen.com / english/advisories/2011/0984
Vendor Advisory
zdnet.com / blog/security/pwn2own-2011-blackberry-falls-to-webkit-browser-attack/8401
zerodayinitiative.com / advisories/ZDI-11-104