CVE-2015-9019

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
05/04/2017
Last modified:
20/04/2025

Description

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* 1.1.29 (including)