Skip to main content

Vendor/product archive

apache / santuario_xml_security_for_java CVEs

Beta · best-effort

6 CVEs tagged to apache / santuario_xml_security_for_java0 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2023-44483

Published Oct 20, 2023

All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8152

Published Jan 21, 2015

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4517

Published Jan 11, 2014

Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2172

Published Aug 20, 2013

jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1