CVE-2011-1202
Summary
| CVE | CVE-2011-1202 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-03-11 02:01:20 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| libxslt - XSLT transformation library | af854a3a-2127-422b-91ae-364da2661108 | git.gnome.org | Patch, Third Party Advisory |
| Bug 684386 – CVE-2011-1202 libxslt: Heap address leak in XLST | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2012:164 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2011:079 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| ASA-2011-194 (RHSA-2011-0471) | af854a3a-2127-422b-91ae-364da2661108 | downloads.avaya.com | Third Party Advisory |
| Security: Multi-browser heap address leak in XSLT | af854a3a-2127-422b-91ae-364da2661108 | scarybeastsecurity.blogspot.com | Third Party Advisory |
| Chrome Releases: Chrome Stable Release | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Google Chrome prior to 10.0.648.127 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| Issue 73716 - chromium - Leak of address of heap object via xslt generate-id() function - An open-source browser project to help move the web forward. - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | Exploit, Issue Tracking, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.