← Back

CVE-2012-2870

nvd nist
Published: Aug 31, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.

Affected (118)

1 product
Iphone Os
1 product
Chrome
1 product
Libxslt
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 6.1.4
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 2.0.0
Version 2.0.1
Version 2.0.2
Version 2.0
Version 2.1.1
Version 2.1
Version 2.2.1
Version 2.2
Version 3.0.1
Version 3.0
Version 3.1.2
Version 3.1.3
Version 3.1
Version 3.2.1
Version 3.2.2
Version 3.2
Version 4.0.1
Version 4.0.2
Version 4.0
Version 4.1
Version 4.2.1
Version 4.2.5
Version 4.2.8
Version 4.3.0
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3.5
Version 5.0.1
Version 5.0
Version 5.1.1
Version 5.1
Version 6.0.1
Version 6.0.2
Version 6.0
Version 6.1.2
Version 6.1.3
Version 6.1
Configuration B
70 vulnerable
Vulnerable SoftwareAffected Versions
Google
Up to 21.0.1180.88
Version 21.0.1180.0
Version 21.0.1180.1
Version 21.0.1180.2
Version 21.0.1180.31
Version 21.0.1180.32
Version 21.0.1180.33
Version 21.0.1180.34
Version 21.0.1180.35
Version 21.0.1180.36
Version 21.0.1180.37
Version 21.0.1180.38
Version 21.0.1180.39
Version 21.0.1180.41
Version 21.0.1180.46
Version 21.0.1180.47
Version 21.0.1180.48
Version 21.0.1180.49
Version 21.0.1180.50
Version 21.0.1180.51
Version 21.0.1180.52
Version 21.0.1180.53
Version 21.0.1180.54
Version 21.0.1180.55
Version 21.0.1180.56
Version 21.0.1180.57
Version 21.0.1180.59
Version 21.0.1180.60
Version 21.0.1180.61
Version 21.0.1180.62
Version 21.0.1180.63
Version 21.0.1180.64
Version 21.0.1180.68
Version 21.0.1180.69
Version 21.0.1180.70
Version 21.0.1180.71
Version 21.0.1180.72
Version 21.0.1180.73
Version 21.0.1180.74
Version 21.0.1180.75
Version 21.0.1180.76
Version 21.0.1180.77
Version 21.0.1180.78
Version 21.0.1180.79
Version 21.0.1180.80
Version 21.0.1180.81
Version 21.0.1180.82
Version 21.0.1180.83
Version 21.0.1180.84
Version 21.0.1180.85
Version 21.0.1180.86
Version 21.0.1180.87
Xmlsoft
Up to 1.1.26
Version 1.1.10
Version 1.1.11
Version 1.1.12
Version 1.1.13
Version 1.1.14
Version 1.1.15
Version 1.1.16
Version 1.1.17
Version 1.1.18
Version 1.1.19
Version 1.1.20
Version 1.1.21
Version 1.1.22
Version 1.1.23
Version 1.1.24
Version 1.1.8
Version 1.1.9

Related CWEs

References (36)

Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.