First published: Thu Oct 14 2010(Updated: )
The browser in Research In Motion (RIM) BlackBerry Device Software 5.0.0.593 Platform 5.1.0.147 on the BlackBerry 9700 does not properly restrict cross-domain execution of JavaScript, which allows remote attackers to bypass the Same Origin Policy via vectors related to a window.open call and an IFRAME element. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Device Software | =5.0.0.593 | |
BlackBerry 9700 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3934 has a high severity rating due to its potential for allowing cross-domain execution of JavaScript.
To fix CVE-2010-3934, update to the latest version of BlackBerry Device Software that addresses this security issue.
CVE-2010-3934 primarily affects BlackBerry Device Software version 5.0.0.593 on the BlackBerry 9700.
CVE-2010-3934 is a cross-site scripting vulnerability that allows attackers to bypass the Same Origin Policy.
Remote attackers can exploit CVE-2010-3934 to execute malicious JavaScript on affected devices.