← back
CVE-2011-1425

CVE-2011-1425

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 8.1%
from disclosure to weapon198 days
Published on NVDApr 3
1st PoC+198d
exploitation probability
8.1%top 6% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.