Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 349

Количество 349

nvd логотип

CVE-2018-15801

больше 7 лет назад

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2018-15801

больше 7 лет назад

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2016-9878

больше 9 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2016-9878

больше 9 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2016-9878

больше 9 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-9878

больше 9 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-1000027

больше 6 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2016-1000027

около 10 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2016-1000027

больше 6 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2016-1000027

больше 6 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remot ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2015-5211

около 9 лет назад

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2015-5211

около 9 лет назад

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2015-5211

около 9 лет назад

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4 ...

CVSS3: 9.6
EPSS: Низкий
ubuntu логотип

CVE-2015-3192

около 10 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2015-3192

около 11 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2015-3192

около 10 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2015-3192

около 10 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not pro ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2015-0201

больше 11 лет назад

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0201

больше 11 лет назад

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-3625

больше 11 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-15801

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.

CVSS3: 7.4
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-15801

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization ...

CVSS3: 7.4
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2016-9878

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
6%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-9878

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 5.6
6%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-9878

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
6%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-9878

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2 ...

CVSS3: 7.5
6%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
32%
Средний
больше 6 лет назад
redhat логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
32%
Средний
около 10 лет назад
nvd логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
32%
Средний
больше 6 лет назад
debian логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remot ...

CVSS3: 9.8
32%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2015-5211

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.

CVSS3: 9.6
3%
Низкий
около 9 лет назад
nvd логотип
CVE-2015-5211

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.

CVSS3: 9.6
3%
Низкий
около 9 лет назад
debian логотип
CVE-2015-5211

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4 ...

CVSS3: 9.6
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-3192

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
3%
Низкий
около 10 лет назад
redhat логотип
CVE-2015-3192

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.3
3%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-3192

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
3%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3192

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not pro ...

CVSS3: 5.5
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-0201

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.

CVSS2: 5
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0201

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 ...

CVSS2: 5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-3625

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVSS2: 5
10%
Средний
больше 11 лет назад

Уязвимостей на страницу