NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39952 | CVE-2013-4330 | Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer. | 2 | 6.8 | Medium | 2017-01-18 | 2014-03-26 | View | |
83160 | CVE-2017-3159 | Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws. | 2 | 7.5 | High | 2017-06-12 | 2017-06-08 | View | |
83980 | CVE-2016-8749 | Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks. | 2 | 7.5 | High | 2017-06-12 | 2017-06-08 | View | |
83233 | CVE-2017-5643 | Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. | 2 | 5.8 | Medium | 2017-04-27 | 2017-03-31 | View | |
46694 | CVE-2012-5575 | Apache CFX 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack." | 2 | 6.4 | Medium | 2017-01-19 | 2013-10-30 | View |
Page 1263 of 17672, showing 5 records out of 88360 total, starting on record 6311, ending on 6315