Show filters
54 Total Results
Displaying 41-50 of 54
Sort by:
Attacker Value
Unknown
CVE-2015-5211
Disclosure Date: May 25, 2017 (last updated November 26, 2024)
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
0
Attacker Value
Unknown
CVE-2016-9878
Disclosure Date: December 29, 2016 (last updated November 25, 2024)
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
0
Attacker Value
Unknown
CVE-2015-3192
Disclosure Date: July 12, 2016 (last updated November 25, 2024)
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
0
Attacker Value
Unknown
CVE-2015-0201
Disclosure Date: March 10, 2015 (last updated October 05, 2023)
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3578
Disclosure Date: February 19, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
0
Attacker Value
Unknown
CVE-2014-3625
Disclosure Date: November 20, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
0
Attacker Value
Unknown
CVE-2014-0054
Disclosure Date: April 17, 2014 (last updated October 05, 2023)
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
0
Attacker Value
Unknown
CVE-2014-1904
Disclosure Date: March 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.
0
Attacker Value
Unknown
CVE-2013-6429
Disclosure Date: January 26, 2014 (last updated October 05, 2023)
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
0
Attacker Value
Unknown
CVE-2013-4152
Disclosure Date: January 23, 2014 (last updated October 05, 2023)
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
0