<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:32:47.162371+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-96611</id>
    <title>EUVD-2026-96611</title>
    <updated>2026-10-03T01:32:47.173524+00:00</updated>
    <content>EUVD-2026-96611</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-96611"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0035</id>
    <title>fkie_cve-2014-0035</title>
    <updated>2026-10-03T01:32:47.173563+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-0035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v45r-rj5x-hpg2</id>
    <title>GHSA-v45r-rj5x-hpg2 — Cleartext Transmission of Sensitive Information in Apache CXF</title>
    <updated>2026-10-03T01:32:47.173607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.cxf:cxf-core</p>
<p>The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v45r-rj5x-hpg2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-0035</id>
    <title>gsd-2014-0035</title>
    <updated>2026-10-03T01:32:47.173634+00:00</updated>
    <content>gsd-2014-0035</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-0035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:0797</id>
    <title>RHSA-2014:0797 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.2.4 update</title>
    <updated>2026-10-03T01:32:47.173646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid CXF: UsernameTokens are sent in plaintext with a Symmetric EncryptBeforeSigning policy CXF: HTML content posted to SOAP endpoint could cause OOM errors CXF: Large invalid content could cause temporary space to fill JAX-RS: Information disclosure via XML eXternal Entity (XXE)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:0797"/>
  </entry>
</feed>
