Lucene search

K
cveAppleCVE-2011-0195
HistoryApr 15, 2011 - 7:55 p.m.

CVE-2011-0195

2011-04-1519:55:00
CWE-200
apple
web.nvd.nist.gov
57
cve-2011-0195
libxslt
apple ios
information security
vulnerability
heap memory
remote attack

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.004

Percentile

74.4%

The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site. NOTE: this may overlap CVE-2011-1202.

Affected configurations

Nvd
Node
appleiphone_osMatch4.3.0
OR
appleiphone_osMatch4.3.1
VendorProductVersionCPE
appleiphone_os4.3.1cpe:/o:apple:iphone_os:4.3.1:::
appleiphone_os4.3.0cpe:/o:apple:iphone_os:4.3.0:::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.004

Percentile

74.4%