<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:11:19 +0000</lastBuildDate>
    <item>
      <title>certfr-2024-avi-0180 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0180</link>
      <description>certfr-2024-avi-0180</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0180</guid>
    </item>
    <item>
      <title>EUVD-2026-113214</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-113214</link>
      <description>EUVD-2026-113214</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-113214</guid>
    </item>
    <item>
      <title>fkie_cve-2012-5784</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2012-5784</link>
      <description>&lt;p&gt;Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject&amp;#39;s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject&amp;#39;s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2012-5784</guid>
    </item>
    <item>
      <title>GHSA-55w9-c3g2-4rrh — Man-in-the-middle attack in Apache Axis</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-55w9-c3g2-4rrh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.axis:axis, Maven: axis:axis&lt;/p&gt;
&lt;p&gt;Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject&amp;#39;s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.axis:axis, Maven: axis:axis&lt;/p&gt;
&lt;p&gt;Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject&amp;#39;s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-55w9-c3g2-4rrh</guid>
    </item>
    <item>
      <title>gsd-2012-5784</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2012-5784</link>
      <description>gsd-2012-5784</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2012-5784</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1497-1 — Security update for axis</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1497-1</link>
      <description>&lt;p&gt;Security update for axis&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for axis&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1497-1</guid>
    </item>
    <item>
      <title>RHSA-2013:0269 — Red Hat Security Advisory: axis security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2013:0269</link>
      <description>&lt;p&gt;axis: missing connection hostname check against X.509 certificate name&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axis: missing connection hostname check against X.509 certificate name&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2013:0269</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:1373-1 — Security update for axis</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:1373-1</link>
      <description>&lt;p&gt;Security update for axis&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for axis&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:1373-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0273 — IBM Maximo Asset Management: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0273</link>
      <description>&lt;p&gt;Ein anonymer Angreifer im angrenzenden Netzbereich kann mehrere Schwachstellen in IBM Maximo Asset Management ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein anonymer Angreifer im angrenzenden Netzbereich kann mehrere Schwachstellen in IBM Maximo Asset Management ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0273</guid>
    </item>
  </channel>
</rss>
