Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1202

Опубликовано: 11 мар. 2011
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 10.0.648.127 (исключая)
cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:*
Версия до 1.1.26 (включая)

EPSS

Процентиль: 76%
0.0102
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 14 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

redhat
больше 14 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

debian
больше 14 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 a ...

github
около 3 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

oracle-oval
почти 13 лет назад

ELSA-2012-1265: libxslt security update (IMPORTANT)

EPSS

Процентиль: 76%
0.0102
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200