Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-1290 | First vendor Publication | 2011-03-11 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS "style handling," nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1290 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12821 | |||
Oval ID: | oval:org.mitre.oval:def:12821 | ||
Title: | DSA-2192-1 chromium-browser -- several | ||
Description: | Several vulnerabilities were discovered in the Chromium browser. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-0779 Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service via a crafted extension. CVE-2011-1290 Integer overflow in WebKit allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2192-1 CVE-2011-0779 CVE-2011-1290 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | chromium-browser |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 | |
Hardware | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2011-09-07 | Name : Mac OS X v10.6.4 Multiple Vulnerabilities (2010-007) File : nvt/gb_macosx_su10-007.nasl |
2011-08-29 | Name : Apple iTunes Arbitrary Code Execution Vulnerability (Mac OS X) File : nvt/secpod_itunes_code_exec_vuln_macosx.nasl |
2011-08-12 | Name : Apple Safari Multiple Vulnerabilities - April 2011 (Mac OS X) File : nvt/gb_apple_safari_mult_vuln_apr11_macosx.nasl |
2011-05-12 | Name : Debian Security Advisory DSA 2192-1 (chromium-browser) File : nvt/deb_2192_1.nasl |
2011-01-24 | Name : FreeBSD Ports: chromium File : nvt/freebsd_chromium.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
72689 | Apple Multiple Products WebKit CSS Style Handling Overflow |
71182 | Google Chrome Unspecified Style Handling Memory Corruption A memory corruption flaw exists in Google Chrome. The program fails to sanitize user-supplied input during style handling, resulting in memory corruption. With a specially crafted web page, a context-dependent attacker can execute arbitrary code. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-01-25 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_libwebkit-121201.nasl - Type : ACT_GATHER_INFO |
2011-04-19 | Name : The remote host contains an application that has multiple vulnerabilities. File : itunes_10_2_2.nasl - Type : ACT_GATHER_INFO |
2011-04-19 | Name : The remote host contains a multimedia application that has multiple vulnerabi... File : itunes_10_2_2_banner.nasl - Type : ACT_GATHER_INFO |
2011-04-14 | Name : The remote host contains a web browser that is affected by several vulnerabil... File : macosx_Safari5_0_5.nasl - Type : ACT_GATHER_INFO |
2011-04-14 | Name : The remote host contains a web browser that is affected by several vulnerabil... File : safari_5_0_5.nasl - Type : ACT_GATHER_INFO |
2011-03-16 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2192.nasl - Type : ACT_GATHER_INFO |
2011-03-14 | Name : The remote host contains a web browser that is affected by a code execution v... File : google_chrome_10_0_648_133.nasl - Type : ACT_GATHER_INFO |
2010-12-08 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_6887828f022911e0b84d00262d5ed8ee.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:05:43 |
|
2024-11-28 12:25:15 |
|
2020-05-23 00:28:07 |
|
2018-10-10 00:19:42 |
|
2017-08-17 09:23:25 |
|
2016-06-28 18:36:06 |
|
2016-04-26 20:39:33 |
|
2014-02-17 11:01:25 |
|
2013-05-10 22:57:19 |
|