Springsource / Spring Framework
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2014-0054 | Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429 | MEDIUM | 6.8 | Apr 17, 2014 |
| CVE-2013-7315 | The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which a… | MEDIUM | 6.8 | Jan 23, 2014 |
| CVE-2013-4152 | Framework: XML External Entity (XXE) injection flaw | MEDIUM | 6.8 | Jan 23, 2014 |
| CVE-2011-2730 | Framework: Information (internal server information, classpath, local working directories, session IDs) disclosure | HIGH | 7.5 | Dec 5, 2012 |
| CVE-2010-1622 | 3.0.3): Arbitrary Java code execution via an HTTP request containing a specially-crafted .jar file | MEDIUM | 6.0 | Jun 21, 2010 |
Showing 1 to 5 of 5 CVEs