Search: "canonical"

158 CVEs found

CVE-2012-3695
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML by leveraging improper URL canonicalization during the hand...

Published: 2012-07-25
Products: 102
Vendors:
apple

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middlewar...

Published: 2013-06-18
Products: 56
Vendors:
sun oracle

Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows remote at...

Published: 2013-08-20
Products: 13
Vendors:
apache
CVE-2013-2172
4.3 MEDIUM

jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signatur...

Published: 2013-08-20
Products: 6
Vendors:
apache
CVE-2013-5910
5.0 MEDIUM

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45, and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors related to Security. NOTE: the previous...

Published: 2014-01-15
Products: 4
Vendors:
oracle

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45, and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors relat...

Published: 2014-01-15
Products: 3
Vendors:
oracle
CVE-2015-3332
4.9 MEDIUM

A certain backport in the TCP Fast Open implementation for the Linux kernel before 3.18 does not properly maintain a count value, which allow local users to cause a denial of service (system crash) vi...

Published: 2015-05-27
Products: 2
Vendors:
linux debian
CVE-2015-1269
4.3 MEDIUM

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP p...

Published: 2015-06-26
Products: 1
Vendors:
google
CVE-2015-2722
10.0 HIGH

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitr...

Published: 2015-07-06
Products: 21
Vendors:
oracle mozilla novell
CVE-2015-2733
10.0 HIGH

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitr...

Published: 2015-07-06
Products: 20
Vendors:
oracle mozilla novell
CVE-2016-2167
6.8 MEDIUM

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate a...

Published: 2016-05-05
Products: 5
Vendors:
apache

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script...

Published: 2016-08-05
Products: 8
Vendors:
oracle mozilla
CVE-2016-9385
6.0 MEDIUM

The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical addr...

Published: 2017-01-23
Products: 20
Vendors:
xen citrix
CVE-2017-14974
5.5 MEDIUM

The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allo...

Published: 2017-10-02
Products: 1
Vendors:
gnu
CVE-2018-3822
9.8 CRITICAL

X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a l...

Published: 2018-03-30
Products: 3
Vendors:
elastic

Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cry...

Published: 2018-07-24
Products: 1
Vendors:
wizkunde

A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can ...

Published: 2018-08-06
Products: 1
Vendors:
nystudio107

OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without ...

Published: 2019-04-17
Products: 1
Vendors:
onelogin

OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without i...

Published: 2019-04-17
Products: 1
Vendors:
onelogin

Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invali...

Published: 2019-04-17
Products: 1
Vendors:
clever