CVEs (66)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 6, 2026 Nov 20, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related...Show more |
2Springsource Vmware2Spring Framework Spring FrameworkMay 6, 2026 Apr 17, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a d...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkApr 29, 2026 Jan 26, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a den...Show more |
2Springsource Vmware2Spring Framework Spring FrameworkApr 29, 2026 Jan 23, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, ca...Show more |
2Springsource Vmware2Spring Framework Spring FrameworkApr 29, 2026 Jan 23, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial o...Show more |
1Vmware 2Spring Framework Spring SecurityApr 29, 2026 Oct 4, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended...Show more |