NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
29043  CVE-2014-0110  Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.    4.3  Medium  2017-01-19  2015-04-22  View
29042  CVE-2014-0109  Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.    4.3  Medium  2017-01-19  2015-04-22  View
86042  CVE-2017-7661  Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in Apache CXF Fediz prior to 1.4.0, 1.3.2 and 1.2.4.    6.8  Medium  2017-07-18  2017-07-07  View
86043  CVE-2017-7662  Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc. A CSRF (Cross Style Request Forgery) style vulnerability has been found in this web application in Apache CXF Fediz prior to 1.4.0 and 1.3.2, meaning that a malicious web application could create new clients, or reset secrets, etc, after the admin user has logged on to the client registration service and the session is still active.    6.8  Medium  2017-07-18  2017-07-07  View
84697  CVE-2017-5656  Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.    Medium  2017-07-18  2017-07-10  View

Page 1270 of 17672, showing 5 records out of 88360 total, starting on record 6346, ending on 6350

Actions