Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 349

Количество 349

github логотип

GHSA-54f6-9mx9-86f7

почти 3 года назад

SaToken privilege escalation vulnerability

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-38808

почти 2 года назад

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2024-38808

почти 2 года назад

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-38808

почти 2 года назад

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-38808

почти 2 года назад

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported vers ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-44794

почти 3 года назад

An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2021-22060

больше 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-22060

больше 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22060

больше 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22060

больше 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-1190

больше 17 лет назад

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2009-1190

больше 17 лет назад

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1190

больше 17 лет назад

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-1190

больше 17 лет назад

Algorithmic complexity vulnerability in the java.util.regex.Pattern.co ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-rqph-vqwm-22vc

около 4 лет назад

Allocation of Resources Without Limits or Throttling in Spring Framework

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-22971

около 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-22971

около 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-22971

около 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22971

около 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v596-fwhq-8x48

почти 8 лет назад

Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-54f6-9mx9-86f7

SaToken privilege escalation vulnerability

CVSS3: 9.8
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2024-38808

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-38808

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

CVSS3: 5.9
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-38808

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-38808

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported vers ...

CVSS3: 4.3
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-44794

An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2009-1190

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

CVSS2: 5
3%
Низкий
больше 17 лет назад
redhat логотип
CVE-2009-1190

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

CVSS2: 4.3
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1190

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

CVSS2: 5
3%
Низкий
больше 17 лет назад
debian логотип
CVE-2009-1190

Algorithmic complexity vulnerability in the java.util.regex.Pattern.co ...

CVSS2: 5
3%
Низкий
больше 17 лет назад
github логотип
GHSA-rqph-vqwm-22vc

Allocation of Resources Without Limits or Throttling in Spring Framework

CVSS3: 6.5
3%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
3%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
3%
Низкий
около 4 лет назад
debian логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-v596-fwhq-8x48

Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core

CVSS3: 5.3
3%
Низкий
почти 8 лет назад

Уязвимостей на страницу