<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:32:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-96611</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-96611</link>
      <description>EUVD-2026-96611</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-96611</guid>
    </item>
    <item>
      <title>fkie_cve-2014-0035</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0035</link>
      <description>&lt;p&gt;The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-0035</guid>
    </item>
    <item>
      <title>GHSA-v45r-rj5x-hpg2 — Cleartext Transmission of Sensitive Information in Apache CXF</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v45r-rj5x-hpg2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-core&lt;/p&gt;
&lt;p&gt;The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-core&lt;/p&gt;
&lt;p&gt;The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v45r-rj5x-hpg2</guid>
    </item>
    <item>
      <title>gsd-2014-0035</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-0035</link>
      <description>gsd-2014-0035</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-0035</guid>
    </item>
    <item>
      <title>RHSA-2014:0797 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.2.4 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2014:0797</link>
      <description>&lt;p&gt;CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid CXF: UsernameTokens are sent in plaintext with a Symmetric EncryptBeforeSigning policy CXF: HTML content posted to SOAP endpoint could cause OOM errors CXF: Large invalid content could cause temporary space to fill JAX-RS: Information disclosure via XML eXternal Entity (XXE)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid CXF: UsernameTokens are sent in plaintext with a Symmetric EncryptBeforeSigning policy CXF: HTML content posted to SOAP endpoint could cause OOM errors CXF: Large invalid content could cause temporary space to fill JAX-RS: Information disclosure via XML eXternal Entity (XXE)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2014:0797</guid>
    </item>
  </channel>
</rss>
