Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-1425

31
FAUCET Score

CVE-2011-1425 describes a critical vulnerability in the XML Security Library (xmlsec) before version 1.2.17, affecting products like WebKit, Apple Safari, and aleksey webkit. This flaw allows remote attackers to create or overwrite arbitrary files by leveraging the libxslt output extension within a ds:Transform element during signature verification. With a CVSS score of 5.1, this vulnerability has a network attack vector, high attack complexity, and potential for partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation in the wild, a Metasploit module (EDB-17993) exists, indicating public exploit code availability, though community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.2.16CPE matchmatch criteria
cpe:2.3:a:aleksey:xml_security_library:*:*:*:*:*:*:*:*
0.0.1CPE matchmatch criteria
cpe:2.3:a:aleksey:xml_security_library:0.0.1:*:*:*:*:*:*:*
0.0.2CPE matchmatch criteria
cpe:2.3:a:aleksey:xml_security_library:0.0.2:*:*:*:*:*:*:*
0.0.2aCPE matchmatch criteria
cpe:2.3:a:aleksey:xml_security_library:0.0.2a:*:*:*:*:*:*:*
0.0.3CPE matchmatch criteria
cpe:2.3:a:aleksey:xml_security_library:0.0.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.1MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
8.06%
Probability of exploitation in next 30 days
EPSS Percentile
94.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-17993 · Oct 18, 2011
This CVE's current EPSS score of 0.0806 is in the 93rd percentile among its peer group of 19,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: xmlsec1-0:1.2.6-3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: xmlsec1-0:1.2.9-8.1.2
View patch

Vendor Advisories (1)

redhatCVE-2011-1425Moderate

xmlsec1: arbitrary file creation when verifying signatures

Mar 31, 2011

References

git.gnome.org / browse/xmlsec/commit
Patch
git.gnome.org / browse/xmlsec/commit
Patch
bugs.webkit.org / show_bug.cgi
bugzilla.redhat.com / show_bug.cgi
Patch
secunia.com / advisories/43920
Vendor Advisory
secunia.com / advisories/44167
secunia.com / advisories/44423
exchange.xforce.ibmcloud.com / vulnerabilities/66506
trac.webkit.org / changeset/79159
aleksey.com / pipermail/xmlsec/2011/009120.html
Patch
debian.org / security/2011/dsa-2219
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2011-0486.html
securityfocus.com / bid/47135
securitytracker.com / id
vupen.com / english/advisories/2011/0855
vupen.com / english/advisories/2011/0858
vupen.com / english/advisories/2011/1010
vupen.com / english/advisories/2011/1172