NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
18445 | CVE-2016-2175 | Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF. | 2 | 7.5 | High | 2017-01-19 | 2017-01-06 | View | |
31751 | CVE-2014-3574 | Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-10 | View | |
83742 | CVE-2017-5644 | Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack. | 2 | 7.1 | High | 2017-03-29 | 2017-03-28 | View | |
10217 | CVE-2011-3620 | Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username. | 2 | 7.5 | High | 2017-01-07 | 2012-08-13 | View | |
45060 | CVE-2012-3467 | Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication. | 2 | 5 | Medium | 2017-01-19 | 2013-01-29 | View |
Page 1280 of 17672, showing 5 records out of 88360 total, starting on record 6396, ending on 6400