The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site. NOTE: this may overlap CVE-2011-1202.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Ios | — | Upgrade to the latest version of Apple iOS | Oct 8, 2014 | Apr 15, 2011 |
| Apple Osx Airport | — | Apply OS X security update 2011-004 | Aug 28, 2015 | Apr 15, 2011 |
| Apple Osx Libxslt | — | Upgrade macOS to the latest versionApply OS X security update 2011-004 | Dec 16, 2011 | Apr 15, 2011 |
| Apple Safari | — | Upgrade to Apple Safari version 5.1Upgrade to Apple Safari version 5.0.6Uninstall Apple Safari on Windows | Jan 5, 2012 | Apr 15, 2011 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Apr 15, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub