xstream
- Products in analyzed data
- 2
- Catalog vulnerabilities
- 37
Severity across 3 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 3 analyzed records
A short verification protects source data and prevents automated AI requests.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2022-41966XStream Denial of Service via stack overflow | Exploitation statusPublic exploit | FixYes | Affected productxstream | Published12/27/2022 | SeverityHigh |
CVE-2022-40152Stack Buffer Overflow in Woodstox | Exploitation statusPublic exploit | FixYes | Affected productWoodstox | Published09/16/2022 | SeverityMedium |
CVE-2022-40151Stack Buffer Overflow in xstream | Exploitation statusPublic exploit | FixNot confirmed | Affected productxstream | Published09/16/2022 | SeverityMedium |
CVE-2021-43859Denial of Service by injecting highly recursive collections or maps in XStream | Exploitation statusPublic exploit | FixNot confirmed | Affected productxstream | Published02/01/2022 | SeverityHigh |
CVE-2021-39150A Server-Side Forgery Request vulnerability in XStream via PriorityQueue unmarshaling | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39152A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39140XStream can cause a Denial of Service | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityMedium |
CVE-2021-39149XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39148XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39147XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39146XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39145XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39141XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39153XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39151XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39139XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39154XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-39144XStream is vulnerable to a Remote Command Execution attack | Exploitation statusKEV | FixNot confirmed | Affected productxstream | Published08/23/2021 | SeverityHigh |
CVE-2021-29505XStream is vulnerable to a Remote Command Execution attack | Exploitation statusNot confirmed | FixYes | Affected productxstream | Published05/28/2021 | SeverityHigh |
CVE-2021-21348XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos) | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21349A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21350XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21351XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21341XStream can cause a Denial of Service | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityHigh |
CVE-2021-21342A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21343XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21344XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21345XStream is vulnerable to a Remote Command Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21346XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2021-21347XStream is vulnerable to an Arbitrary Code Execution attack | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published03/22/2021 | SeverityMedium |
CVE-2020-26258Server-Side Forgery Request can be activated unmarshalling with XStream | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published12/16/2020 | SeverityMedium |
CVE-2020-26259XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published12/16/2020 | SeverityMedium |
CVE-2020-26217Remote Code Execution in XStream | Exploitation statusNot confirmed | FixYes | Affected productxstream | Published11/16/2020 | SeverityHigh |
CVE-2019-10173CVE-2019-10173 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxstream | Published07/23/2019 | SeverityHigh |
CVE-2013-7285CVE-2013-7285 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published05/15/2019 | SeverityUnknown |
CVE-2017-7957CVE-2017-7957 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published04/29/2017 | SeverityUnknown |
CVE-2016-3674CVE-2016-3674 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published05/17/2016 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan