Vulnerabilities (CVE)

Filtered by vendor Oracle Subscribe
Filtered by product Communications Messaging Server
Total 41 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-0228 3 Apache, Fedoraproject, Oracle 14 James, Pdfbox, Fedora and 11 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.