The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade www-client/firefox.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/icecat.Upgrade www-client/firefox-bin.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Apr 15, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 9, 2011 |
| Ubuntu | — | Upgrade firefoxUpgrade xulrunner-1.9.2 | Nov 19, 2024 | Apr 15, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub