<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Ant (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ant.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ant-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Ant (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-35371 – Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35371</guid>
    <pubDate>Fri, 29 Nov 2024 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35371</strong></p>
  <p>Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries without restrictions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37779 – WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37779</guid>
    <pubDate>Mon, 23 Sep 2024 20:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37779</strong></p>
  <p>WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-75</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-46983 – sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46983</guid>
    <pubDate>Thu, 19 Sep 2024 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-46983</strong></p>
  <p>sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32656 – Ant Media Server is live streaming engine software. A local privilege escalation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32656</guid>
    <pubDate>Mon, 22 Apr 2024 23:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32656</strong></p>
  <p>Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.6.0 through 2.8.2 allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability arises from Ant Media Server running with Java Management Extensions (JMX) enabled and authentication disabled on localhost o…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-3651 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3651</guid>
    <pubDate>Tue, 08 Aug 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-3651</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Commerce Software allows SQL Injection.  This issue affects E-Commerce Software: before 11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-37647 – SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37647</guid>
    <pubDate>Mon, 31 Jul 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-37647</strong></p>
  <p>SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23306 – The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23306</guid>
    <pubDate>Tue, 23 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23306</strong></p>
  <p>The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call its `add` method, override arbitrary memory and hijack the execution of the device's firmware.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23303 – The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23303</guid>
    <pubDate>Tue, 23 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23303</strong></p>
  <p>The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's firmware.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-31741 – There is a command injection vulnerability in the Linksys E2000 router with firm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31741</guid>
    <pubDate>Tue, 23 May 2023 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-31741</strong></p>
  <p>There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-31742 – There is a command injection vulnerability in the Linksys WRT54GL router with fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31742</guid>
    <pubDate>Mon, 22 May 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-31742</strong></p>
  <p>There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-31707 – SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31707</guid>
    <pubDate>Fri, 19 May 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-31707</strong></p>
  <p>SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22602 – When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a speciall...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22602</guid>
    <pubDate>Sat, 14 Jan 2023 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22602</strong></p>
  <p>When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass.  The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching. Mitigation: Update to Apache Shiro 1.11.0, or set the following Spring Boot co…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38733 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38733</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38733</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38732 – SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38732</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38732</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38731 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38731</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38731</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38730 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38730</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38730</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38729 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38729</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38729</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38737 – SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38737</guid>
    <pubDate>Fri, 28 Oct 2022 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38737</strong></p>
  <p>SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38736 – SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38736</guid>
    <pubDate>Fri, 28 Oct 2022 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38736</strong></p>
  <p>SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38734 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38734</guid>
    <pubDate>Fri, 28 Oct 2022 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38734</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11979 – As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of tem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11979</guid>
    <pubDate>Thu, 01 Oct 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11979</strong></p>
  <p>As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-379</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9810 – There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Ant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9810</guid>
    <pubDate>Mon, 17 Jul 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9810</strong></p>
  <p>There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-2849 – SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 31...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2849</guid>
    <pubDate>Tue, 07 Jul 2015 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-2849</strong></p>
  <p>SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices, when https is used, allows remote attackers to execute arbitrary SQL commands via the ppli parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-5483 – Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5483</guid>
    <pubDate>Tue, 16 Oct 2007 23:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-5483</strong></p>
  <p>Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin or ANT) in IBM WebSphere Application Server 5.x and 6.0.x has unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-3223 – Format string vulnerability in CA Integrated Threat Management (ITM), eTrust Ant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-3223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-3223</guid>
    <pubDate>Tue, 27 Jun 2006 21:05:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-3223</strong></p>
  <p>Format string vulnerability in CA Integrated Threat Management (ITM), eTrust Antivirus (eAV), and eTrust PestPatrol (ePP) r8 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a scan job with format strings in the description field.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-3223">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
