<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:27:35.881606+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2014-0225</id>
    <title>CVE-2014-0225</title>
    <updated>2026-10-06T15:27:35.920369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Pivotal Spring Framework</p>
<p>When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2014-0225"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-4774-1</id>
    <title>USN-4774-1 — libspring-java vulnerabilities</title>
    <updated>2026-10-06T15:27:35.920435+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java</p>
<p>Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)</p>
<p>Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)</p>
<p>It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)</p>
<p>It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of service, disclosure of information
or other unspecified impact. This issue only affected Ubuntu 14.04 ESM. 
(CVE-2014-0225)</p>
<p>It was discovered that Spring Framework incorrectly handled certain URLs. A
remote attacker could possibly use this issue to read arbitrary files, 
resulting in a directory traversal attack. This issue only affected Ubuntu
14.04 ESM. (CVE-2014-3625, CVE-2014-3578)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-4774-1"/>
  </entry>
</feed>
