İçeriğe atla
Noroxi

springsource kayıtları

springsource üreticisine ait 10 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%60
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

10 kayıt
  • CVE-2014-0054
    54Planlayın

    The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external ent

    OrtaCVSS 6,8İstismar yokEPSS %91

    springsource · spring framework17 Nis 2014

  • CVE-2010-1622
    40Planlayın

    SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute a

    OrtaCVSS 6,0Kavram kanıtıEPSS %52

    springsource · spring framework21 Haz 2010

  • CVE-2013-4152
    35İzleyin

    The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, wh

    OrtaCVSS 6,8İstismar yokEPSS %26

    springsource · spring framework23 Oca 2014

  • CVE-2011-2730
    34İzleyin

    VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (E

    YüksekCVSS 7,5İstismar yokEPSS %12

    springsource · spring framework5 Ara 2012

  • CVE-2013-7315
    29İzleyin

    The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLIn

    OrtaCVSS 6,8İstismar yokEPSS %5

    springsource · spring framework23 Oca 2014

  • CVE-2009-1190
    21İzleyin

    Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used w

    OrtaCVSS 5,0İstismar yokEPSS %3

    sun · jdk27 Nis 2009

  • CVE-2012-1833
    20İzleyin

    VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers t

    OrtaCVSS 5,0İstismar yokEPSS %1

    springsource · grails28 Eyl 2012

  • CVE-2009-2897
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface

    OrtaCVSS 4,3İstismar yokEPSS %2

    springsource · application management suite13 Eki 2009

  • CVE-2009-2907
    17İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) befor

    OrtaCVSS 4,3Kavram kanıtıEPSS %1

    springsource · application management suite24 Mar 2010

  • CVE-2009-2898
    15İzleyin

    Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.

    DüşükCVSS 3,5Kavram kanıtıEPSS %2

    springsource · application management suite13 Eki 2009