Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-1712 | First vendor Publication | 2011-04-15 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1712 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-200 | Information Exposure |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:14467 | |||
Oval ID: | oval:org.mitre.oval:def:14467 | ||
Title: | The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. | ||
Description: | The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-1712 | Version: | 16 |
Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Mozilla Seamonkey Mozilla Firefox |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-04-22 | Name : Mozilla Firefox Information Disclosure Vulnerability (Windows) File : nvt/gb_firefox_info_disc_vuln.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
72094 | Mozilla Multiple Products XSLT generate-id() Function Heap Address Informatio... Mozilla Firefox and SeaMonkey contains a flaw that may lead to an unauthorized information disclosure. Â The issue is triggered when the XSLT 'generate-id()' function in functions.c in libxslt returns a string which reveals a specific valid address of an object on the memory heap to an attacker using an XML document with a call to the XSLT generate-id XPath function. This may make it easier for a context-dependent attacker to exploit a memory corruption flaw. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-01-08 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201301-01.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:05:27 |
|
2024-11-28 12:25:34 |
|
2024-11-01 01:16:31 |
|
2024-10-22 12:16:26 |
|
2024-08-02 12:16:27 |
|
2024-08-02 01:04:38 |
|
2024-02-10 01:14:50 |
|
2024-02-02 01:15:58 |
|
2024-02-01 12:04:32 |
|
2023-09-05 12:14:57 |
|
2023-09-05 01:04:24 |
|
2023-09-02 12:15:00 |
|
2023-09-02 01:04:28 |
|
2023-08-12 12:18:08 |
|
2023-08-12 01:04:29 |
|
2023-08-11 12:15:05 |
|
2023-08-11 01:04:37 |
|
2023-08-06 12:14:30 |
|
2023-08-06 01:04:29 |
|
2023-08-04 12:14:35 |
|
2023-08-04 01:04:30 |
|
2023-07-14 12:14:34 |
|
2023-07-14 01:04:28 |
|
2023-03-29 01:16:29 |
|
2023-03-28 12:04:34 |
|
2022-10-11 12:12:59 |
|
2022-10-11 01:04:14 |
|
2021-05-04 12:14:24 |
|
2021-04-22 01:15:39 |
|
2020-10-14 01:06:29 |
|
2020-10-03 01:06:30 |
|
2020-05-29 01:05:59 |
|
2020-05-23 01:44:23 |
|
2020-05-23 00:28:23 |
|
2017-11-22 12:03:57 |
|
2017-11-21 12:03:08 |
|
2017-09-19 09:24:25 |
|
2017-08-17 09:23:30 |
|
2016-06-28 18:38:23 |
|
2016-04-26 20:43:26 |
|
2014-02-17 11:02:00 |
|
2013-05-10 22:59:24 |
|