CVE-2011-1202 describes an information disclosure vulnerability in the xsltGenerateIdFunction within libxslt 1.1.26 and earlier, impacting products like Google Chrome. Attackers can exploit this by crafting malicious XML documents that, when processed, reveal sensitive heap memory addresses. This vulnerability has a CVSS score of 4.3, indicating a medium severity. It requires medium attack complexity (AC:M) and can be exploited remotely (AV:N) without authentication (Au:N), leading to a potential compromise of confidentiality (C:P) by exposing memory layout. There is no evidence of active exploitation, and no public exploit code is available in Metasploit or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, suggesting low public awareness and limited current threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.648.127CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
<= 1.1.26CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.