Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.8
CVE-2012-5786
- EPSS 0.1%
- Veröffentlicht 04.11.2012 22:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field o...
4.3
CVE-2012-3451
- EPSS 9.97%
- Veröffentlicht 24.09.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
9.8
CVE-2010-2076
- EPSS 7.83%
- Veröffentlicht 19.08.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows...