Filtered by vendor Apache Subscriptions
Filtered by product Ws-xmlrpc Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2016-5004 1 Apache 1 Ws-xmlrpc 2024-11-21 N/A
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.
CVE-2016-5003 2 Apache, Redhat 4 Ws-xmlrpc, Enterprise Linux, Jboss Fuse and 1 more 2024-11-21 N/A
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.