Skip to content
Noroxi

xstream records

37 published records for vendor xstream.

All records

37 records
  • XStream is vulnerable to a Remote Command Execution attack

    HighCVSS 8.5KEVWeaponizedEPSS 98%

    xstream · xstreamAug 23, 2021

  • CVE-2019-10173
    68This week

    It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw.

    CriticalCVSS 9.8No exploitEPSS 95%

    xstream · xstreamJul 23, 2019

  • CVE-2013-7285
    64This week

    Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run

    CriticalCVSS 9.8Proof of conceptEPSS 84%

    xstream · xstreamMay 15, 2019

  • CVE-2021-21346
    62This week

    XStream is vulnerable to an Arbitrary Code Execution attack

    CriticalCVSS 9.8No exploitEPSS 76%

    xstream · xstreamMar 22, 2021

  • CVE-2021-21344
    62This week

    XStream is vulnerable to an Arbitrary Code Execution attack

    CriticalCVSS 9.8No exploitEPSS 76%

    xstream · xstreamMar 22, 2021

  • CVE-2020-26217
    61This week

    Remote Code Execution in XStream

    HighCVSS 8.8Proof of conceptEPSS 85%

    xstream · xstreamNov 16, 2020

  • CVE-2021-21351
    61This week

    XStream is vulnerable to an Arbitrary Code Execution attack

    CriticalCVSS 9.1Proof of conceptEPSS 82%

    xstream · xstreamMar 22, 2021

  • CVE-2021-21345
    61This week

    XStream is vulnerable to a Remote Command Execution attack

    CriticalCVSS 9.9Proof of conceptEPSS 72%

    xstream · xstreamMar 22, 2021

  • XStream is vulnerable to a Remote Command Execution attack

    HighCVSS 8.8Proof of conceptEPSS 77%

    xstream · xstreamMay 28, 2021

  • Server-Side Forgery Request can be activated unmarshalling with XStream

    HighCVSS 7.7Proof of conceptEPSS 82%

    xstream · xstreamDec 15, 2020

  • XStream can cause a Denial of Service

    HighCVSS 7.5Proof of conceptEPSS 78%

    xstream · xstreamMar 22, 2021

  • XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling

    MediumCVSS 6.8Proof of conceptEPSS 82%

    xstream · xstreamDec 15, 2020

  • A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or

    CriticalCVSS 9.1No exploitEPSS 50%

    xstream · xstreamMar 22, 2021

  • A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or

    HighCVSS 8.6Proof of conceptEPSS 47%

    xstream · xstreamMar 22, 2021

  • XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights

    HighCVSS 7.5No exploitEPSS 47%

    xstream · xstreamMar 22, 2021

  • XStream is vulnerable to an Arbitrary Code Execution attack

    CriticalCVSS 9.8No exploitEPSS 15%

    xstream · xstreamMar 22, 2021

  • XStream is vulnerable to an Arbitrary Code Execution attack

    CriticalCVSS 9.8No exploitEPSS 14%

    xstream · xstreamMar 22, 2021

  • XStream is vulnerable to an Arbitrary Code Execution attack

    HighCVSS 8.5Proof of conceptEPSS 16%

    xstream · xstreamAug 23, 2021

  • XStream is vulnerable to an Arbitrary Code Execution attack

    HighCVSS 8.5Proof of conceptEPSS 14%

    xstream · xstreamAug 23, 2021

  • A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling

    HighCVSS 8.5Proof of conceptEPSS 11%

    xstream · xstreamAug 23, 2021

  • Stack Buffer Overflow in Woodstox

    HighCVSS 7.5No exploitEPSS 20%

    xstream · xstreamSep 16, 2022

  • XStream is vulnerable to an Arbitrary Code Execution attack

    HighCVSS 8.8No exploitEPSS 5%

    xstream · xstreamAug 23, 2021

  • XStream is vulnerable to an Arbitrary Code Execution attack

    HighCVSS 8.5No exploitEPSS 5%

    xstream · xstreamAug 23, 2021

  • XStream is vulnerable to an Arbitrary Code Execution attack

    HighCVSS 8.5No exploitEPSS 5%

    xstream · xstreamAug 23, 2021

  • XStream is vulnerable to an Arbitrary Code Execution attack

    HighCVSS 8.5No exploitEPSS 5%

    xstream · xstreamAug 23, 2021