Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-0161
HistoryMar 11, 2011 - 12:00 a.m.

CVE-2011-0161

2011-03-1100:00:00
ubuntu.com
ubuntu.com
14

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

76.5%

WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not
properly handle the Attr.style accessor, which allows remote attackers to
bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token
sequences via a crafted web site.

Notes

Author Note
jdstrand qt4-x11 unmaintained upstream (see README.webkit for details)

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

76.5%