VULNERABILITY INTELLIGENCE
CVE-2011-1202
CVSS score4.3 MEDIUM
EPSS probability2.44%
CISA KEVNot currently listed
Published2011-03-11
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Description
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Weakness classification
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Primary references
- cve@mitre.org — Exploit, Issue Tracking, Patch, Vendor Advisory
- cve@mitre.org — Third Party Advisory
- cve@mitre.org — Patch, Third Party Advisory
- cve@mitre.org — Vendor Advisory
- cve@mitre.org — Third Party Advisory
- cve@mitre.org — Third Party Advisory
- cve@mitre.org — Third Party Advisory
- cve@mitre.org — Third Party Advisory, VDB Entry
- cve@mitre.org — Permissions Required
- cve@mitre.org — Issue Tracking, Third Party Advisory
- cve@mitre.org — Third Party Advisory, VDB Entry
- cve@mitre.org — Third Party Advisory