NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
39952  CVE-2013-4330  Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.    6.8  Medium  2017-01-18  2014-03-26  View
83160  CVE-2017-3159  Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.    7.5  High  2017-06-12  2017-06-08  View
83980  CVE-2016-8749  Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.    7.5  High  2017-06-12  2017-06-08  View
83233  CVE-2017-5643  Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.    5.8  Medium  2017-04-27  2017-03-31  View
46694  CVE-2012-5575  Apache CFX 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."    6.4  Medium  2017-01-19  2013-10-30  View

Page 1263 of 17672, showing 5 records out of 88360 total, starting on record 6311, ending on 6315

Actions