render software vulnerabilities
vulnerabilities.aspcode.net
Searching render software vulnerabilities
Cross site scripting vulnerabilities in Apache
vulnerabilities
|
scripting
|
Apache
|
Cross
|
site
|
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on Tuesday, July 24, 2007, is one such variant.
Safari after 2.0 in Apple Mac OS X 10.3.9 allow
Safari
|
Apple
|
after
|
Mac
|
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
** DISPUTED ** NOTE: the vendor has disputed t
DISPUTED
|
** DISPUTED ** NOTE: the vendor has disputed this issue. Cross-site scripting (XSS) vulnerability in lemoon 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the q parameter. NOTE: the vendor has disputed this issue, saying "Sites are built on top of ASP.NET and you use lemoon core objects to easily manage and render content. The XSS vuln. you are referring to exists in one of our public sites built on lemoon i.e. a custom made site (as all sites are). The problem exists in a UserControl that handles form input and is in no way related to the lemoon core product."
Buffer overflow in the X render (Xrender) exten
overflow
|
render
|
Buffer
|
Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.
Interpretation conflict between Internet Explor
Interpretation
|
presentation
|
protection
|
mechanisms
|
characters
|
attackers
|
stripped
|
possibly
|
Explorer
|
Internet
|
browsers
|
conflict
|
content
|
legible
|
between
|
filters
|
Mozilla
|
Firefox
|
bypass
|
remote
|
visual
|
modify
|
render
|
Opera
|
which
|
using
|
could
|
ASCII
|
allow
|
might
|
pages
|
other
|
such
|
text
|
but
|
not
|
web
|
set
|
8th
|
via
|
bit
|
Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly bypass protection mechanisms such as content filters via ASCII characters with the 8th bit set, which could be stripped by Internet Explorer to render legible text, but not when using other browsers. NOTE: there has been significant discussion about this issue, and as of Sunday, June 25, 2006, it is not clear where the responsibility for this issue lies, although it might be due to vagueness within the associated standards. NOTE: this might only be exploitable with certain encodings.
Integer overflow in the ProcRenderAddGlyphs fun
ProcRenderAddGlyphs
|
extension
|
function
|
overflow
|
Integer
|
Render
|
XOrg
|
Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.
phpwcms 1.2.5-DEV and earlier, and 1.1 before R
phpwcms_code_snippets/mail_file_formphp
|
nome_evento
|
arbitrary
|
attackers
|
parameter
|
argument
|
execute
|
crafted
|
phpwcms
|
125-DEV
|
earlier
|
before
|
remote
|
allows
|
code
|
via
|
RC4
|
phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via a crafted argument to the nome_evento parameter to phpwcms_code_snippets/mail_file_form.php and (2) sample_ext_php/mail_file_form.php, which is processed by the render_PHPcode function.
phpwcms 1.2.5-DEV and earlier, and 1.1 before R
arguments
|
arbitrary
|
attackers
|
execute
|
phpwcms
|
125-DEV
|
earlier
|
crafted
|
before
|
allows
|
remote
|
code
|
RC4
|
via
|
phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_evento and (2) email_eventonome_evento parameters to phpwcms_code_snippets/mail_file_form.php and sample_ext_php/mail_file_form.php, which is processed by the render_PHPcode function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
The X render (Xrender) extension in X.org X Win
render
|
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.
The cmdjob utility in Autodesk Backburner 3.0.2
Backburner
|
Autodesk
|
utility
|
cmdjob
|
The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers by queueing jobs that contain these commands. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.
Microsoft Windows Media Player (WMP) 9 on Windo
Microsoft
|
Windows
|
Player
|
Media
|
Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file.
Multiple PHP remote file inclusion vulnerabilit
vulnerabilities
|
inclusion
|
Multiple
|
phpWCMS
|
remote
|
file
|
PHP
|
Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in phpwcms_template/inc_script/frontend_render/navigation/.
Software vulnerabilities results 1 to 13 of 13
Page:
1