Search: "canonical"

158 CVEs found

CVE-2000-0024
6.4 MEDIUM

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerabi...

Published: 1999-12-21
Products: 3
Vendors:
microsoft
CVE-2000-0770
6.4 MEDIUM

IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restriction...

Published: 2000-10-20
Products: 2
Vendors:
microsoft
CVE-2002-1347
9.8 CRITICAL

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonical...

Published: 2002-12-18
Products: 3
Vendors:
apple cyrusimap
CVE-2003-1025
4.3 MEDIUM

Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL,...

Published: 2004-01-20
Products: 1
Vendors:
microsoft
CVE-2004-0444
10.0 HIGH

Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 ...

Published: 2004-07-07
Products: 23
Vendors:
symantec
CVE-2004-2294
4.3 MEDIUM

Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences ...

Published: 2004-12-31
Products: 15
Vendors:
francisco_burzi
CVE-2007-1762
5.0 MEDIUM

Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / ...

Published: 2007-03-30
Products: 3
Vendors:
mozilla

Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Win...

Published: 2007-05-16
Products: 2
Vendors:
comodo

Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows lo...

Published: 2007-05-16
Products: 6
Vendors:
comodo microsoft checkpoint
CVE-2008-2665
5.0 MEDIUM

Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the...

Published: 2008-06-20
Products: 1
Vendors:
php
CVE-2008-4250
9.8 CRITICAL

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a craft...

Published: 2008-10-23
Products: 18
Vendors:
microsoft

Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-depend...

Published: 2010-05-14
Products: 2
Vendors:
microsoft
CVE-2010-2105
10.0 HIGH

Google Chrome before 5.0.375.55 does not properly follow the Safe Browsing specification's requirements for canonicalization of URLs, which has unspecified impact and remote attack vectors.

Published: 2010-05-28
Products: 1
Vendors:
google
CVE-2010-1390
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary we...

Published: 2010-06-11
Products: 74
Vendors:
apple microsoft
CVE-2010-3863
5.0 MEDIUM

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrict...

Published: 2010-11-05
Products: 2
Vendors:
apache jsecurity
CVE-2011-0244
4.3 MEDIUM

WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds.

Published: 2011-07-21
Products: 79
Vendors:
apple microsoft
CVE-2011-3126
5.0 MEDIUM

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

Published: 2011-08-10
Products: 4
Vendors:
wordpress
CVE-2011-4675
6.4 MEDIUM

The pathname canonicalization functionality in io/filesystem/filesystem.cc in Widelands before 15.1 expands leading ~ (tilde) characters to home-directory pathnames but does not restrict use of these ...

Published: 2011-12-05
Products: 20
Vendors:
widelands

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent Sma...

Published: 2012-06-12
Products: 20
Vendors:
joyent netbsd microsoft illumos sun +3 more

Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted loc...

Published: 2012-06-21
Products: 1
Vendors:
icu-project