Search CVE reports


Toggle filters

51 – 60 of 60 results


CVE-2016-9878

Low priority

Some fixes available 2 of 6

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Not affected Not affected Not affected
Show less packages

CVE-2015-3192

Low priority

Some fixes available 2 of 8

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Not affected Not affected Not affected
Show less packages

CVE-2014-3578

Medium priority

Some fixes available 1 of 8

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Not affected Not affected Not affected
Show less packages

CVE-2014-3625

Medium priority

Some fixes available 1 of 8

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Not affected Not affected Not affected
Show less packages

CVE-2014-0054

Medium priority
Ignored

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java
Show less packages

CVE-2014-1904

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Not affected
Show less packages

CVE-2013-6429

Medium priority
Ignored

The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Not affected
Show less packages

CVE-2013-7315

Medium priority
Ignored

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Not affected
Show less packages

CVE-2013-4152

Medium priority
Ignored

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service,...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java
Show less packages

CVE-2011-2894

Medium priority
Ignored

Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security...

3 affected packages

libspring-2.5-java, libspring-java, libspring-security-2.0-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-2.5-java Not in release
libspring-java Not affected
libspring-security-2.0-java Not in release
Show less packages