<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:48:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-96781</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-96781</link>
      <description>EUVD-2026-96781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-96781</guid>
    </item>
    <item>
      <title>fkie_cve-2014-0225</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0225</link>
      <description>&lt;p&gt;When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-0225</guid>
    </item>
    <item>
      <title>GHSA-f93f-g33r-8pcp — Improper Restriction of XML External Entity Reference in Spring Framework</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f93f-g33r-8pcp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-webmvc&lt;/p&gt;
&lt;p&gt;When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-webmvc&lt;/p&gt;
&lt;p&gt;When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f93f-g33r-8pcp</guid>
    </item>
    <item>
      <title>gsd-2014-0225</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-0225</link>
      <description>gsd-2014-0225</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-0225</guid>
    </item>
    <item>
      <title>RHSA-2014:1351 — Red Hat Security Advisory: Red Hat JBoss Fuse/A-MQ 6.1.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2014:1351</link>
      <description>&lt;p&gt;CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid CXF: UsernameTokens are sent in plaintext with a Symmetric EncryptBeforeSigning policy Shiro: successful authentication without specifying user name or password Xalan-Java: insufficient constraints in secure processing feature CXF: HTML content posted to SOAP endpoint could cause OOM errors CXF: Large invalid content could cause temporary space to fill netty: DoS via memory exhaustion during data aggregation Framework: Information disclosure via SSRF&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid CXF: UsernameTokens are sent in plaintext with a Symmetric EncryptBeforeSigning policy Shiro: successful authentication without specifying user name or password Xalan-Java: insufficient constraints in secure processing feature CXF: HTML content posted to SOAP endpoint could cause OOM errors CXF: Large invalid content could cause temporary space to fill netty: DoS via memory exhaustion during data aggregation Framework: Information disclosure via SSRF&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2014:1351</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-0225</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0225</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0225</guid>
    </item>
  </channel>
</rss>
