Filtered by vendor Apache Subscriptions
Filtered by product Ws-xmlrpc Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2016-5003 1 Apache 1 Ws-xmlrpc 2024-01-22 N/A
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
CVE-2016-5004 1 Apache 1 Ws-xmlrpc 2017-06-16 N/A
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.