SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-1290

Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown…

HIGH 10.0EPSS 9.75%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (9.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS "style handling," nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
9.75% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-189
Affected
apple/webkit · rim/blackberry torch 9800 firmware · rim/blackberry torch 9800
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.