CVE-2011-3970 describes an out-of-bounds read vulnerability in libxslt, specifically affecting Google Chrome versions prior to 17.0.963.46, as well as products from SUSE and xmlsoft. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and remote attack vector, with a potential impact of denial of service. There is no evidence of active exploitation, nor are there known public exploit codes in Metasploit, Nuclei, or ExploitDB. While it has received some community discussion and media coverage, it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.0.963.46CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
<= 1.1.26CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:ltss:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.