Back to Database
Status published
Medium
CVE-2015-9019
In libxslt 1.1.29 and earlier, the EXSLT math.random function was...
Vulnerability Description
In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-9019
Credits & Attribution
No credits recorded in the NVD database.
References
More from xmlsoft
View All →CVE-2025-32415
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in...
Low
2.9
CVE-2025-32414
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory...
Medium
5.6
CVE-2025-27113
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL...
Low
2.9
CVE-2025-24928
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based...
High
7.8
CVE-2025-24855
numbers.c in libxslt before 1.1.43 has a use-after-free because, in...
High
7.8
Affected Vendor
xmlsoft
View all reports →Affected Software
libxslt
Vulnerable Versions:
0
Timeline
Official Publish:
April 5th, 2017
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.