peter bassill · operator
$ cve CVE-2011-1425 JSON

CVE-2011-1425 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 8.1% (pctl 95)

Patch early

A public exploit exists.

Description

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS8.06% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2011-04-04
Last modified2026-06-16

Affected (2)

VendorProduct
alekseyxml security library
applewebkit

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD