NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46694 | CVE-2012-5575 | Apache CFX 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack." | 2 | 6.4 | Medium | 2017-01-19 | 2013-10-30 | View | |
83233 | CVE-2017-5643 | Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. | 2 | 5.8 | Medium | 2017-04-27 | 2017-03-31 | View | |
83980 | CVE-2016-8749 | Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks. | 2 | 7.5 | High | 2017-06-12 | 2017-06-08 | View | |
83160 | CVE-2017-3159 | Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws. | 2 | 7.5 | High | 2017-06-12 | 2017-06-08 | View | |
39952 | CVE-2013-4330 | Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer. | 2 | 6.8 | Medium | 2017-01-18 | 2014-03-26 | View |
Page 16410 of 17672, showing 5 records out of 88360 total, starting on record 82046, ending on 82050