Debian Libspring-Java vulnerabilities
22 known vulnerabilities affecting debian/libspring-java.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM8LOW7
Vulnerabilities
Page 2 of 2
CVE-2015-3192P4LOWCVSS 5.5fixed in libspring-java 4.1.9-1 (bookworm)2015
CVE-2015-3192 [MEDIUM] CVE-2015-3192: libspring-java - Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly proc...
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
Scope: local
bookworm: resolved (fixed in 4.1.9-1)
bullseye: resolved (fixed in 4.1.9-1)
debian
CVE-2014-1904P4MEDIUMCVSS 4.3fixed in libspring-java 3.0.6.RELEASE-13 (bookworm)2014
CVE-2014-1904 [MEDIUM] CVE-2014-1904: libspring-java - Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java i...
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-13)
bullseye: resolved (fixed in 3.0.6.RELEA
debian
← Previous2 / 2