CVE-2011-1712
published 2011-04-15CVE-2011-1712: The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.07%
61.4th percentile
The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Affected
150 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.18 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8rr4-9q45-q5mw: The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker
ghsa_unreviewed·2022-05-17
CVE-2011-1712 [MEDIUM] CWE-200 GHSA-8rr4-9q45-q5mw: The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker
The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Red Hat
firefox: information leak due to XSLT
vendor_redhat·2011-03-09·CVSS 4.3
CVE-2011-1712 [MEDIUM] firefox: information leak due to XSLT
firefox: information leak due to XSLT
The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Package: firefox (Red Hat Enterprise Linux 4) - Affected
Package: firefox (Red Hat Enterprise Linux 5) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.htmlhttp://www.mozilla.org/security/announce/2011/mfsa2011-18.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=640339https://exchange.xforce.ibmcloud.com/vulnerabilities/66836https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14467http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.htmlhttp://www.mozilla.org/security/announce/2011/mfsa2011-18.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=640339https://exchange.xforce.ibmcloud.com/vulnerabilities/66836https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14467
2011-04-15
Published