<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:10:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-01754</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-01754</link>
      <description>bdu:2019-01754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-01754</guid>
    </item>
    <item>
      <title>certfr-2019-avi-331 — Une vulnérabilité a été découverte dans IBM QRadar. Elle permet à un
attaquant de provoquer un déni de service à distan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-331</link>
      <description>certfr-2019-avi-331</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-331</guid>
    </item>
    <item>
      <title>EUVD-2026-165089</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-165089</link>
      <description>EUVD-2026-165089</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-165089</guid>
    </item>
    <item>
      <title>fkie_cve-2018-15756</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-15756</link>
      <description>&lt;p&gt;Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-15756</guid>
    </item>
    <item>
      <title>GHSA-ffvq-7w96-97p7 — Denial of Service in Spring Framework</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ffvq-7w96-97p7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-core&lt;/p&gt;
&lt;p&gt;Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-core&lt;/p&gt;
&lt;p&gt;Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ffvq-7w96-97p7</guid>
    </item>
    <item>
      <title>gsd-2018-15756</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-15756</link>
      <description>gsd-2018-15756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-15756</guid>
    </item>
    <item>
      <title>RHSA-2020:0983 — Red Hat Security Advisory: Red Hat Fuse 7.6.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0983</link>
      <description>&lt;p&gt;jquery: Cross-site scripting via cross-domain ajax requests logback: Serialization vulnerability in SocketServer and ServerSocketReceiver js-jquery: XSS in responses from cross-origin ajax requests apache-commons-compress: ZipArchiveInputStream.read() fails to identify correct EOF allowing for DoS via crafted zip jetty: full server path revealed when using the default Error Handling springframework: DoS Attack via Range Requests spring-data-api: potential information disclosure through maliciously crafted example value in ExampleMatcher undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed c3p0: loading XML configuration leads to denial of service HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using PRIORITY frames results in excessive resource consumption HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth HTTP/2: 0-length headers lead to denial of service HTTP/2: request for large response leads to denial of service HTTP/2: flood using empty frames results in excessive resource consumption infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods undertow: Information leak in requests for directories without trailing slashes jetty: using specially formatted URL against DefaultServlet or ResourceHandler leads to XSS conditions jetty: error path information disclosure spring-secur…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jquery: Cross-site scripting via cross-domain ajax requests logback: Serialization vulnerability in SocketServer and ServerSocketReceiver js-jquery: XSS in responses from cross-origin ajax requests apache-commons-compress: ZipArchiveInputStream.read() fails to identify correct EOF allowing for DoS via crafted zip jetty: full server path revealed when using the default Error Handling springframework: DoS Attack via Range Requests spring-data-api: potential information disclosure through maliciously crafted example value in ExampleMatcher undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed c3p0: loading XML configuration leads to denial of service HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using PRIORITY frames results in excessive resource consumption HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth HTTP/2: 0-length headers lead to denial of service HTTP/2: request for large response leads to denial of service HTTP/2: flood using empty frames results in excessive resource consumption infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods undertow: Information leak in requests for directories without trailing slashes jetty: using specially formatted URL against DefaultServlet or ResourceHandler leads to XSS conditions jetty: error path information disclosure spring-secur…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0983</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-15756</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-15756</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-15756</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</guid>
    </item>
  </channel>
</rss>
