* Use the reference for the mime type to get the format Fixes: CVE-2014-0082 * Escape format, negative_format and units options of number helpers Fixes: CVE-2014-0081