Vulnerability · NVD
CVE-2011-1202
CVE-2011-1202, Severity pending severity (CVSS —): 2 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- -
- Exploitation
- 2.4 %
- Tracked apps
- 2
- Still exposed
- 0
EPSS, predicted over 30 days
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
EPSS
2.44%
above median
percentile 83.1%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Affected <10.0.648.127 Fixed in 10.0.648.127 Latest tracked - undetermined
-
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <10.0.648.127 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <10.0.648.127 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |