Applications

Version 15.1 by Nicolas Gregoire on 2012/01/13 15:08

Browsers

ApplicationXSLT Engine Vulnerabilities
Webkit-based browserlibxsltFile creation (CVE-2011-1774)
FirefoxTransformiix
Opera Presto
Internet ExplorerMS XML

Web (server side)

ApplicationXSLT Engine Vulnerabilities
LiferayXalan-J File disclosure (CVE-2011-1502 / CVE-2011-1503), code execution (CVE-2011-1571)
PHP 5libxsltFile creation (No CVE, No patch)
Sharepoint MS XMLFile disclosure (CVE-2011-1892 aka MS11-074 )
DotNetNukeMS XMLFile disclosure (No CVE, patched in v06.00.00 of the XML module)

Online services

W3C XSLT Gateway : Saxon
Online Toolz : libxslt
Shell Tools : libxslt
XSLT Java applet : XSLTC from Xalan-J

Office software

ApplicationXSLT Engine Vulnerabilities
Adobe ReaderModified Sablotron Memory corruption (Linux only)
LiferalibxsltFile creation
OpenOfficelibxslt

Security

xmlsec : libxslt

Lasso : libxslt

ApplicationXSLT Engine Vulnerabilities
LiferayXalan-J File disclosure, code execution
PHP 5libxsltFile creation
Sharepoint MS XML File disclosure
DotNetNukeMS XML File disclosure