Wiki source code of Applications

Last modified by Nicolas Gregoire on 2012/07/23 14:23

Hide last authors
Nicolas Gregoire 26.1 1 {{toc/}}
Nicolas Gregoire 1.1 2
Nicolas Gregoire 26.1 3 = Web (client side) =
4
Nicolas Gregoire 13.1 5 |=Application|=XSLT Engine |=Vulnerabilities
Nicolas Gregoire 25.1 6 |[[Webkit>>Application_Webkit]]|[[libxslt>>Engine_libxslt]]|File creation ([[CVE-2011-1774>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1774||rel="__blank" title="CVE-2011-1774"]])
Nicolas Gregoire 34.1 7 |[[Firefox>>Application_Firefox]]|[[Transformiix>>Engine_Transformiix]]|Memory corruption ([[MFSA 2012-08>>http://www.mozilla.org/security/announce/2012/mfsa2012-08.html||rel="__blank" title="MFSA 2012-08"]] aka [[CVE-2012-0449>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0449||rel="__blank" title="CVE-2012-0449"]])\\
Nicolas Gregoire 36.1 8 |[[Opera>>Application_Opera]] |[[Presto>>Engine_Presto]]|Misc crashes (DSK-355332 and DSK-355334)\\
Nicolas Gregoire 13.1 9 |Internet Explorer|[[MS XML>>Engine_MSXML]]|\\
Nicolas Gregoire 1.1 10
Nicolas Gregoire 26.1 11 = Web (server side) =
Nicolas Gregoire 1.1 12
Nicolas Gregoire 9.1 13 |=Application|=XSLT Engine |=Vulnerabilities
Nicolas Gregoire 18.1 14 |[[Liferay>>Application_Liferay]]|[[Xalan-J>>Engine_XalanJ]] |File disclosure ([[CVE-2011-1502>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1502||rel="__blank" title="CVE-2011-1502"]] and [[CVE-2011-1503>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1503||rel="__blank" title="CVE-2011-1503"]])
15 Code execution ([[CVE-2011-1571>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1571||rel="__blank" title="CVE-2011-1571"]])
Nicolas Gregoire 28.1 16 |[[PHP 5>>Application_PHP5]]|[[libxslt>>Engine_libxslt]]|Arbitrary file creation ([[CVE-2012-0057>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0057||rel="__blank" title="CVE-2012-0057"]], corrected in v5.3.9)
Nicolas Gregoire 39.1 17 |[[Sharepoint>>Application_Sharepoint]]|[[MS XML>>Engine_MSXML]]|XML External Entity : File disclosure, ... ([[CVE-2011-1892>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1892||rel="__blank" title="CVE-2011-1892"]] aka [[MS11-074>>http://technet.microsoft.com/security/bulletin/MS11-074||rel="__blank" title="MS11-074"]])
18 |[[DotNetNuke>>Application_DotNetNuke]]|[[MS XML>>Engine_MSXML]]|XML External Entity : File disclosure, ... (No CVE, patched in v06.00.00 of the XML module)
Nicolas Gregoire 31.1 19 |[[MoinMoin>>Application_MoinMoin]]|[[4Suite>>Engine_4Suite]]|Arbitrary file disclosure and creation ([[CVE-2012-xxxx>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-xxxx||rel="__blank" title="CVE-2012-xxxx"]])
Nicolas Gregoire 1.1 20
Nicolas Gregoire 26.1 21 = Online services =
Nicolas Gregoire 5.1 22
Nicolas Gregoire 21.1 23 |=Application |=XSLT engine
24 | [[W3C XSLT Gateway>>http://www.w3.org/2005/08/online_xslt/]] | [[Saxon>>Engine_Saxon]]
25 | [[Online Toolz>>http://online-toolz.com/tools/xslt-transformation.php]]|[[ libxslt>>Engine_libxslt]]
26 | [[Shell Tools>>http://www.shell-tools.net/index.php?op=xslt]]| [[libxslt>>Engine_libxslt]]
27 | [[XSLT Java applet>>http://unindented.org/projects/xslt-tester-applet/]]| XSLTC from [[Xalan-J>>Engine_XalanJ]]
28
Nicolas Gregoire 26.1 29 = Office software =
Nicolas Gregoire 1.1 30
Nicolas Gregoire 11.1 31 |=Application|=XSLT Engine |=Vulnerabilities
Nicolas Gregoire 14.1 32 |Adobe Reader|Modified [[Sablotron>>Engine_Sablotron]] |Memory corruption (Linux only)
33 |Lifera|[[libxslt>>Engine_libxslt]]|File creation
34 |OpenOffice|[[libxslt>>Engine_libxslt]]|\\
Nicolas Gregoire 11.1 35
Nicolas Gregoire 26.1 36 = Security =
Nicolas Gregoire 2.1 37
Nicolas Gregoire 12.1 38 |=Application|=XSLT Engine |=Vulnerabilities
Nicolas Gregoire 20.1 39 |[[xmlsec>>Application_xmlsec]]|[[libxslt>>Engine_libxslt]]|File creation ([[CVE-2011-1425>>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1425||rel="__blank" title="CVE-2011-1425"]])
Nicolas Gregoire 19.1 40 |Lasso|[[libxslt>>Engine_libxslt]]|\\
41 |Unnamed application verifying XML-DSig signatures|[[Xalan-J>>Engine_XalanJ]]|Remote code execution
Nicolas Gregoire 40.1 42
Nicolas Gregoire 40.2 43 = Databases =
Nicolas Gregoire 40.1 44
45 |=Application|=XSLT Engine |=Vulnerabilities
Nicolas Gregoire 40.3 46 |Postgres SQL|[[libxslt>>Engine_libxslt]]|File disclosure, File creation