V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2012-2870
DEB
MediumConfirmedExploit available

libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attacke…

CVSS
4.3
Medium
EPSS
0.01
p71
Published
2012-01-01
Updated
2012-01-01
Description

libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.

Tags · CWE
RCE
CWE-399
CWE-416
Affected products
Chrome ≤ 21.0.1180.88ChromeLibxslt ≤ 1.1.26Libxslt
CVSS vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.007 · p71
Known exploited (KEV)
No
Known exploits — Сканер-ВС
35810
exploitdb · https://www.exploit-db.com/exploits/35810
Enterprise
Affected software
ProductVendorStatus
chromium-browserTracked
chromium-browserTracked
libxsltTracked
libxsltTracked
libxsltTracked
libxsltTracked
chrome*Tracked
iphone_os*Tracked
libxslt*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities