Vulnerabilities > Redhat > Jboss Aerogear > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-07-01 CVE-2014-3648 Resource Exhaustion vulnerability in Redhat Jboss Aerogear 1.0.0
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken.
network
low complexity
redhat CWE-400
5.0
2019-11-04 CVE-2014-3649 Cross-site Scripting vulnerability in Redhat Jboss Aerogear 20140919
JBoss AeroGear has reflected XSS via the password field
network
redhat CWE-79
4.3