Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 349

Количество 349

redhat логотип

CVE-2014-3625

больше 11 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2014-3625

больше 11 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-3625

больше 11 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 th ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-3578

больше 11 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-3578

почти 12 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-3578

больше 11 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-3578

больше 11 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.x befo ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-1904

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-1904

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-1904

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-1904

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/Form ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-0225

около 9 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2014-0225

около 12 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-0225

около 9 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2014-0225

около 9 лет назад

When processing user provided XML documents, the Spring Framework 4.0. ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2014-0054

больше 12 лет назад

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

CVSS2: 6.8
EPSS: Критический
redhat логотип

CVE-2014-0054

больше 12 лет назад

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

CVSS2: 5
EPSS: Критический
nvd логотип

CVE-2014-0054

больше 12 лет назад

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

CVSS2: 6.8
EPSS: Критический
debian логотип

CVE-2014-0054

больше 12 лет назад

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Frame ...

CVSS2: 6.8
EPSS: Критический
ubuntu логотип

CVE-2013-7315

больше 12 лет назад

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-3625

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVSS2: 5
10%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-3625

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVSS2: 5
10%
Средний
больше 11 лет назад
debian логотип
CVE-2014-3625

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 th ...

CVSS2: 5
10%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-3578

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

CVSS2: 5
6%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-3578

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

CVSS2: 5
6%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-3578

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

CVSS2: 5
6%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-3578

Directory traversal vulnerability in Pivotal Spring Framework 3.x befo ...

CVSS2: 5
6%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-1904

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

CVSS2: 4.3
3%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-1904

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

CVSS2: 4.3
3%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1904

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

CVSS2: 4.3
3%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1904

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/Form ...

CVSS2: 4.3
3%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-0225

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2014-0225

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS2: 5
2%
Низкий
около 12 лет назад
nvd логотип
CVE-2014-0225

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
2%
Низкий
около 9 лет назад
debian логотип
CVE-2014-0225

When processing user provided XML documents, the Spring Framework 4.0. ...

CVSS3: 8.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2014-0054

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

CVSS2: 6.8
91%
Критический
больше 12 лет назад
redhat логотип
CVE-2014-0054

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

CVSS2: 5
91%
Критический
больше 12 лет назад
nvd логотип
CVE-2014-0054

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

CVSS2: 6.8
91%
Критический
больше 12 лет назад
debian логотип
CVE-2014-0054

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Frame ...

CVSS2: 6.8
91%
Критический
больше 12 лет назад
ubuntu логотип
CVE-2013-7315

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

CVSS2: 6.8
5%
Низкий
больше 12 лет назад

Уязвимостей на страницу