<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:15:52 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-06637</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06637</link>
      <description>bdu:2022-06637</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06637</guid>
    </item>
    <item>
      <title>EUVD-2026-99359</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-99359</link>
      <description>EUVD-2026-99359</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-99359</guid>
    </item>
    <item>
      <title>fkie_cve-2014-3623</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-3623</link>
      <description>&lt;p&gt;Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-3623</guid>
    </item>
    <item>
      <title>GHSA-99v3-9x35-c5vf — Improper Authentication in Apache WSS4J</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-99v3-9x35-c5vf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.ws.security:wss4j, Maven: org.apache.wss4j:wss4j-ws-security-dom&lt;/p&gt;
&lt;p&gt;Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.ws.security:wss4j, Maven: org.apache.wss4j:wss4j-ws-security-dom&lt;/p&gt;
&lt;p&gt;Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-99v3-9x35-c5vf</guid>
    </item>
    <item>
      <title>gsd-2014-3623</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-3623</link>
      <description>gsd-2014-3623</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-3623</guid>
    </item>
    <item>
      <title>RHSA-2014:2019 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.3.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2014:2019</link>
      <description>&lt;p&gt;CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix CXF: Improper security semantics enforcement of SAML SubjectConfirmation methods&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix CXF: Improper security semantics enforcement of SAML SubjectConfirmation methods&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2014:2019</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1375 — JFrog Artifactory: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</guid>
    </item>
  </channel>
</rss>
