CVE-2016-9878
- EPSS 4.93%
- Published 29.12.2016 09:59:00
- Last modified 12.04.2025 10:46:40
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
CVE-2015-3192
- EPSS 1.38%
- Published 12.07.2016 19:59:00
- Last modified 12.04.2025 10:46:40
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) vi...
- EPSS 0.29%
- Published 10.03.2015 14:59:04
- Last modified 12.04.2025 10:46:40
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
- EPSS 18.93%
- Published 20.11.2014 17:50:00
- Last modified 12.04.2025 10:46:40
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
CVE-2014-0054
- EPSS 34.58%
- Published 17.04.2014 14:55:06
- Last modified 12.04.2025 10:46:40
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct ...
CVE-2013-6429
- EPSS 58.21%
- Published 26.01.2014 16:58:10
- Last modified 11.04.2025 00:51:21
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CS...
CVE-2013-7315
- EPSS 0.52%
- Published 23.01.2014 21:55:05
- Last modified 11.04.2025 00:51:21
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and c...
CVE-2013-4152
- EPSS 89.01%
- Published 23.01.2014 21:55:04
- Last modified 11.04.2025 00:51:21
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF at...
CVE-2011-2894
- EPSS 15.08%
- Published 04.10.2011 10:55:09
- Last modified 11.04.2025 00:51:21
Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and exec...