CVE-2011-3254: XSS
Published Oct 14, 2011
·Updated
Cross-site scripting (XSS) vulnerability in Calendar in Apple iOS before 5 allows remote attackers to inject arbitrary web script or HTML via an invitation note.
Affected Software
13 affected components
apple iPhone OS=4.3.2
apple iPhone OS=4.2.9
apple iPhone OS=4.2.8
apple iPhone OS=4.3.4
apple iPhone OS=4.3.5
apple iPhone OS=4.3.1
apple iPhone OS=4.2.5
apple iPhone OS=4.2
apple iPhone OS=4.3.5
apple iPhone OS=4.3.5
apple iPhone OS=4.2.1
apple iPhone OS=4.3.3
apple iPhone OS=4.3.0
Event History
Oct 14, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3254?
CVE-2011-3254 is considered a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2011-3254?
To fix CVE-2011-3254, users should upgrade their iOS device to version 5 or later.
3
What type of vulnerability is CVE-2011-3254?
CVE-2011-3254 is a cross-site scripting (XSS) vulnerability affecting Calendar in Apple iOS.
4
Which versions of iOS are affected by CVE-2011-3254?
CVE-2011-3254 affects various iOS versions prior to 5, including 4.3.2, 4.2.x, and 4.3.x.
5
Can CVE-2011-3254 lead to remote code execution?
While CVE-2011-3254 allows for arbitrary web script or HTML injection, it does not directly result in remote code execution.