HIGH · 7.5

CVE-2011-1295

WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corrup...

Vulnerability Description

WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corruption), conduct cross-site scripting (XSS) attacks, or possibly have unspecified other impact via unknown vectors.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
GoogleChrome< 10.0.648.204
AppleSafari< 5.0.6
AppleIphone Os< 5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1295?

CVE-2011-1295 is a vulnerability with a CVSS score of 7.5 (HIGH). WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corrup...

How severe is CVE-2011-1295?

CVE-2011-1295 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1295?

Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Apple Safari, Apple Iphone Os.