<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:07:54 +0000</lastBuildDate>
    <item>
      <title>CVE-2014-0225</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2014-0225</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Pivotal Spring Framework&lt;/p&gt;
&lt;p&gt;When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Pivotal Spring Framework&lt;/p&gt;
&lt;p&gt;When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2014-0225</guid>
    </item>
    <item>
      <title>USN-4774-1 — libspring-java vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-4774-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)&lt;/p&gt;
&lt;p&gt;Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)&lt;/p&gt;
&lt;p&gt;It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)&lt;/p&gt;
&lt;p&gt;It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of service, disclosure of information
or other unspecified impact. This issue only affected Ubuntu 14.04 ESM. 
(CVE-2014-0225)&lt;/p&gt;
&lt;p&gt;It was discovered that Spring Framework incorrectly handled certain URLs. A
remote attacker could possibly use this issue to read arbitrary files, 
resulting in a directory traversal attack. This issue only affected Ubuntu
14.04 ESM. (CVE-2014-3625, CVE-2014-3578)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)&lt;/p&gt;
&lt;p&gt;Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)&lt;/p&gt;
&lt;p&gt;It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)&lt;/p&gt;
&lt;p&gt;It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of service, disclosure of information
or other unspecified impact. This issue only affected Ubuntu 14.04 ESM. 
(CVE-2014-0225)&lt;/p&gt;
&lt;p&gt;It was discovered that Spring Framework incorrectly handled certain URLs. A
remote attacker could possibly use this issue to read arbitrary files, 
resulting in a directory traversal attack. This issue only affected Ubuntu
14.04 ESM. (CVE-2014-3625, CVE-2014-3578)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-4774-1</guid>
    </item>
  </channel>
</rss>
