Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1202

Опубликовано: 11 мар. 2011
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 10.0.648.127 (исключая)
cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:*
Версия до 1.1.26 (включая)

EPSS

Процентиль: 70%
0.00644
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 15 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

redhat
почти 15 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

debian
почти 15 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 a ...

github
больше 3 лет назад

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

oracle-oval
больше 13 лет назад

ELSA-2012-1265: libxslt security update (IMPORTANT)

EPSS

Процентиль: 70%
0.00644
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200