CVE-2011-1202

N/A Unknown
Published: March 11, 2011 Modified: April 29, 2026
View on NVD

Description

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://code.google.com/p/chromium/issues/detail?id=73716
Source: cve@mitre.org
Exploit Issue Tracking Patch Vendor Advisory
http://downloads.avaya.com/css/P8/documents/100144158
Source: cve@mitre.org
Third Party Advisory
http://www.securityfocus.com/bid/46785
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2011/0628
Source: cve@mitre.org
Permissions Required
https://bugzilla.redhat.com/show_bug.cgi?id=684386
Source: cve@mitre.org
Issue Tracking Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/65966
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://code.google.com/p/chromium/issues/detail?id=73716
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Issue Tracking Patch Vendor Advisory
http://downloads.avaya.com/css/P8/documents/100144158
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://git.gnome.org/browse/libxslt/commit/?id=ecb6bcb8d1b7e44842edde3929f412d46b40c89f
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
http://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:079
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2012:164
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.securityfocus.com/bid/46785
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2011/0628
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
https://bugzilla.redhat.com/show_bug.cgi?id=684386
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/65966
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14244
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

24 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.5%
82th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

xmlsoft google