Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-3192

Опубликовано: 12 июл. 2016
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.5

Описание

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

4.3.14-1
cosmic

not-affected

4.3.14-1
devel

not-affected

4.3.14-1
disco

not-affected

4.3.14-1
eoan

not-affected

4.3.14-1
esm-apps/bionic

not-affected

4.3.14-1
esm-apps/focal

not-affected

4.3.14-1
esm-apps/jammy

not-affected

4.3.14-1
esm-apps/xenial

released

3.2.13-5ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 78%
0.01232
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
около 10 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
nvd
около 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
debian
около 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not pro ...

CVSS3: 5.5
github
почти 7 лет назад

Pivotal Spring Framework DoS Attack with XML Input

EPSS

Процентиль: 78%
0.01232
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3