CVE-2011-0161
published 2011-03-11CVE-2011-0161: WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.65%
74.2th percentile
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 4.2 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6p2p-vj22-cmm3: WebKit, as used in Apple Safari before 5
ghsa_unreviewed·2022-05-17
CVE-2011-0161 [MEDIUM] CWE-20 GHSA-6p2p-vj22-cmm3: WebKit, as used in Apple Safari before 5
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
OSV
CVE-2011-0161: WebKit, as used in Apple Safari before 5
osv·2011-03-11·CVSS 4.3
CVE-2011-0161 [MEDIUM] CVE-2011-0161: WebKit, as used in Apple Safari before 5
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://support.apple.com/kb/HT4564http://support.apple.com/kb/HT4566http://www.securityfocus.com/bid/46814http://www.securitytracker.com/id?1025182https://exchange.xforce.ibmcloud.com/vulnerabilities/66000http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://support.apple.com/kb/HT4564http://support.apple.com/kb/HT4566http://www.securityfocus.com/bid/46814http://www.securitytracker.com/id?1025182https://exchange.xforce.ibmcloud.com/vulnerabilities/66000
2011-03-11
Published