NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
38254 | CVE-2013-2155 | Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions. | 2 | 5.8 | Medium | 2017-01-18 | 2013-08-27 | View | |
35360 | CVE-2014-8152 | Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document. | 2 | 5 | Medium | 2017-01-19 | 2015-02-20 | View | |
40114 | CVE-2013-4517 | Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures. | 2 | 4.3 | Medium | 2017-01-18 | 2015-04-22 | View | |
29014 | CVE-2014-0074 | Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password. | 2 | 7.5 | High | 2017-01-19 | 2014-10-07 | View | |
15198 | CVE-2010-3863 | Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI. | 2 | 5 | Medium | 2017-01-18 | 2010-11-11 | View |
Page 1282 of 17672, showing 5 records out of 88360 total, starting on record 6406, ending on 6410