5.1

CVE-2011-1425

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AlekseyXml Security Library Version <= 1.2.16
AlekseyXml Security Library Version0.0.1
AlekseyXml Security Library Version0.0.2
AlekseyXml Security Library Version0.0.2a
AlekseyXml Security Library Version0.0.3
AlekseyXml Security Library Version0.0.4
AlekseyXml Security Library Version0.0.5
AlekseyXml Security Library Version0.0.6
AlekseyXml Security Library Version0.0.7
AlekseyXml Security Library Version0.0.8
AlekseyXml Security Library Version0.0.9
AlekseyXml Security Library Version0.0.10
AlekseyXml Security Library Version0.0.11
AlekseyXml Security Library Version0.0.12
AlekseyXml Security Library Version0.0.13
AlekseyXml Security Library Version0.0.14
AlekseyXml Security Library Version0.0.15
AlekseyXml Security Library Version0.1.0
AlekseyXml Security Library Version0.1.1
AlekseyXml Security Library Version1.0.0
AlekseyXml Security Library Version1.0.0 Updaterc1
AlekseyXml Security Library Version1.0.1
AlekseyXml Security Library Version1.0.2
AlekseyXml Security Library Version1.0.3
AlekseyXml Security Library Version1.0.4
AlekseyXml Security Library Version1.1.0
AlekseyXml Security Library Version1.1.1
AlekseyXml Security Library Version1.1.2
AlekseyXml Security Library Version1.2.0
AlekseyXml Security Library Version1.2.1
AlekseyXml Security Library Version1.2.2
AlekseyXml Security Library Version1.2.3
AlekseyXml Security Library Version1.2.4
AlekseyXml Security Library Version1.2.5
AlekseyXml Security Library Version1.2.6
AlekseyXml Security Library Version1.2.7
AlekseyXml Security Library Version1.2.8
AlekseyXml Security Library Version1.2.9
AlekseyXml Security Library Version1.2.10
AlekseyXml Security Library Version1.2.11
AlekseyXml Security Library Version1.2.13
AlekseyXml Security Library Version1.2.14
AlekseyXml Security Library Version1.2.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.9% 0.927
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P