Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-2870


libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.


Published

2012-08-31T19:55:01.077

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple iphone_os ≤ 6.1.4 Yes
Operating System apple iphone_os 1.0.0 Yes
Operating System apple iphone_os 1.0.1 Yes
Operating System apple iphone_os 1.0.2 Yes
Operating System apple iphone_os 1.1.0 Yes
Operating System apple iphone_os 1.1.1 Yes
Operating System apple iphone_os 1.1.2 Yes
Operating System apple iphone_os 1.1.3 Yes
Operating System apple iphone_os 1.1.4 Yes
Operating System apple iphone_os 1.1.5 Yes
Operating System apple iphone_os 2.0 Yes
Operating System apple iphone_os 2.0.0 Yes
Operating System apple iphone_os 2.0.1 Yes
Operating System apple iphone_os 2.0.2 Yes
Operating System apple iphone_os 2.1 Yes
Operating System apple iphone_os 2.1.1 Yes
Operating System apple iphone_os 2.2 Yes
Operating System apple iphone_os 2.2.1 Yes
Operating System apple iphone_os 3.0 Yes
Operating System apple iphone_os 3.0.1 Yes
Operating System apple iphone_os 3.1 Yes
Operating System apple iphone_os 3.1.2 Yes
Operating System apple iphone_os 3.1.3 Yes
Operating System apple iphone_os 3.2 Yes
Operating System apple iphone_os 3.2.1 Yes
Operating System apple iphone_os 3.2.2 Yes
Operating System apple iphone_os 4.0 Yes
Operating System apple iphone_os 4.0.1 Yes
Operating System apple iphone_os 4.0.2 Yes
Operating System apple iphone_os 4.1 Yes
Operating System apple iphone_os 4.2.1 Yes
Operating System apple iphone_os 4.2.5 Yes
Operating System apple iphone_os 4.2.8 Yes
Operating System apple iphone_os 4.3.0 Yes
Operating System apple iphone_os 4.3.1 Yes
Operating System apple iphone_os 4.3.2 Yes
Operating System apple iphone_os 4.3.3 Yes
Operating System apple iphone_os 4.3.5 Yes
Operating System apple iphone_os 5.0 Yes
Operating System apple iphone_os 5.0.1 Yes
Operating System apple iphone_os 5.1 Yes
Operating System apple iphone_os 5.1.1 Yes
Operating System apple iphone_os 6.0 Yes
Operating System apple iphone_os 6.0.1 Yes
Operating System apple iphone_os 6.0.2 Yes
Operating System apple iphone_os 6.1 Yes
Operating System apple iphone_os 6.1.2 Yes
Operating System apple iphone_os 6.1.3 Yes
Application google chrome ≤ 21.0.1180.88 Yes
Application google chrome 21.0.1180.0 Yes
Application google chrome 21.0.1180.1 Yes
Application google chrome 21.0.1180.2 Yes
Application google chrome 21.0.1180.31 Yes
Application google chrome 21.0.1180.32 Yes
Application google chrome 21.0.1180.33 Yes
Application google chrome 21.0.1180.34 Yes
Application google chrome 21.0.1180.35 Yes
Application google chrome 21.0.1180.36 Yes
Application google chrome 21.0.1180.37 Yes
Application google chrome 21.0.1180.38 Yes
Application google chrome 21.0.1180.39 Yes
Application google chrome 21.0.1180.41 Yes
Application google chrome 21.0.1180.46 Yes
Application google chrome 21.0.1180.47 Yes
Application google chrome 21.0.1180.48 Yes
Application google chrome 21.0.1180.49 Yes
Application google chrome 21.0.1180.50 Yes
Application google chrome 21.0.1180.51 Yes
Application google chrome 21.0.1180.52 Yes
Application google chrome 21.0.1180.53 Yes
Application google chrome 21.0.1180.54 Yes
Application google chrome 21.0.1180.55 Yes
Application google chrome 21.0.1180.56 Yes
Application google chrome 21.0.1180.57 Yes
Application google chrome 21.0.1180.59 Yes
Application google chrome 21.0.1180.60 Yes
Application google chrome 21.0.1180.61 Yes
Application google chrome 21.0.1180.62 Yes
Application google chrome 21.0.1180.63 Yes
Application google chrome 21.0.1180.64 Yes
Application google chrome 21.0.1180.68 Yes
Application google chrome 21.0.1180.69 Yes
Application google chrome 21.0.1180.70 Yes
Application google chrome 21.0.1180.71 Yes
Application google chrome 21.0.1180.72 Yes
Application google chrome 21.0.1180.73 Yes
Application google chrome 21.0.1180.74 Yes
Application google chrome 21.0.1180.75 Yes
Application google chrome 21.0.1180.76 Yes
Application google chrome 21.0.1180.77 Yes
Application google chrome 21.0.1180.78 Yes
Application google chrome 21.0.1180.79 Yes
Application google chrome 21.0.1180.80 Yes
Application google chrome 21.0.1180.81 Yes
Application google chrome 21.0.1180.82 Yes
Application google chrome 21.0.1180.83 Yes
Application google chrome 21.0.1180.84 Yes
Application google chrome 21.0.1180.85 Yes
Application google chrome 21.0.1180.86 Yes
Application google chrome 21.0.1180.87 Yes
Application xmlsoft libxslt ≤ 1.1.26 Yes
Application xmlsoft libxslt 1.1.8 Yes
Application xmlsoft libxslt 1.1.9 Yes
Application xmlsoft libxslt 1.1.10 Yes
Application xmlsoft libxslt 1.1.11 Yes
Application xmlsoft libxslt 1.1.12 Yes
Application xmlsoft libxslt 1.1.13 Yes
Application xmlsoft libxslt 1.1.14 Yes
Application xmlsoft libxslt 1.1.15 Yes
Application xmlsoft libxslt 1.1.16 Yes
Application xmlsoft libxslt 1.1.17 Yes
Application xmlsoft libxslt 1.1.18 Yes
Application xmlsoft libxslt 1.1.19 Yes
Application xmlsoft libxslt 1.1.20 Yes
Application xmlsoft libxslt 1.1.21 Yes
Application xmlsoft libxslt 1.1.22 Yes
Application xmlsoft libxslt 1.1.23 Yes
Application xmlsoft libxslt 1.1.24 Yes

References