NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
38254  CVE-2013-2155  Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.    5.8  Medium  2017-01-18  2013-08-27  View
35360  CVE-2014-8152  Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.    Medium  2017-01-19  2015-02-20  View
40114  CVE-2013-4517  Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.    4.3  Medium  2017-01-18  2015-04-22  View
29014  CVE-2014-0074  Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.    7.5  High  2017-01-19  2014-10-07  View
15198  CVE-2010-3863  Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.    Medium  2017-01-18  2010-11-11  View

Page 1282 of 17672, showing 5 records out of 88360 total, starting on record 6406, ending on 6410

Actions