xstream records
37 published records for vendor xstream.
Researcher profile
- Entered KEV
- 1 · 2.7%
- Weaponized
- 1 · 2.7%
- Pre-auth RCE
- 7
- With a fix record
- 100%
- Median publish → KEV
- 564 days
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type15
- CWE-502 Deserialization of Untrusted Data5
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-121 Stack-based Buffer Overflow2
The weakness classes this vendor ships most often: where to look.
CWEAll records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
93Now | CVE-2021-39144Weaponized | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | High8.5 | KEV | 98.1% | Aug 23, 2021 |
68This week | CVE-2019-10173No exploit | It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw.xstream · xstream · CWE-94 | Critical9.8 | — | 95.0% | Jul 23, 2019 |
64This week | CVE-2013-7285Proof of concept | Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run xstream · xstream · CWE-78 | Critical9.8 | — | 84.4% | May 15, 2019 |
62This week | CVE-2021-21346No exploit | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Critical9.8 | — | 76.4% | Mar 22, 2021 |
62This week | CVE-2021-21344No exploit | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Critical9.8 | — | 76.0% | Mar 22, 2021 |
61This week | CVE-2020-26217Proof of concept | Remote Code Execution in XStreamxstream · xstream · CWE-78 | High8.8 | — | 85.0% | Nov 16, 2020 |
61This week | CVE-2021-21351Proof of concept | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Critical9.1 | — | 82.1% | Mar 22, 2021 |
61This week | CVE-2021-21345Proof of concept | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | Critical9.9 | — | 72.3% | Mar 22, 2021 |
58Plan | CVE-2021-29505Proof of concept | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | High8.8 | — | 77.2% | May 28, 2021 |
55Plan | CVE-2020-26258Proof of concept | Server-Side Forgery Request can be activated unmarshalling with XStreamxstream · xstream · CWE-918 | High7.7 | — | 81.8% | Dec 15, 2020 |
53Plan | CVE-2021-21341Proof of concept | XStream can cause a Denial of Servicexstream · xstream · CWE-400 | High7.5 | — | 77.8% | Mar 22, 2021 |
52Plan | CVE-2020-26259Proof of concept | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshallingxstream · xstream · CWE-78 | Medium6.8 | — | 82.4% | Dec 15, 2020 |
51Plan | CVE-2021-21342No exploit | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or xstream · xstream · CWE-502 | Critical9.1 | — | 50.0% | Mar 22, 2021 |
48Plan | CVE-2021-21349Proof of concept | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or xstream · xstream · CWE-502 | High8.6 | — | 46.8% | Mar 22, 2021 |
44Plan | CVE-2021-21343No exploit | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rightsxstream · xstream · CWE-73 | High7.5 | — | 46.7% | Mar 22, 2021 |
44Plan | CVE-2021-21350No exploit | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Critical9.8 | — | 15.2% | Mar 22, 2021 |
43Plan | CVE-2021-21347No exploit | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Critical9.8 | — | 14.3% | Mar 22, 2021 |
39Monitor | CVE-2021-39141Proof of concept | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | High8.5 | — | 16.1% | Aug 23, 2021 |
38Monitor | CVE-2021-39146Proof of concept | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | High8.5 | — | 14.3% | Aug 23, 2021 |
37Monitor | CVE-2021-39152Proof of concept | A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshalingxstream · xstream · CWE-502 | High8.5 | — | 11.4% | Aug 23, 2021 |
36Monitor | CVE-2022-40152No exploit | Stack Buffer Overflow in Woodstoxxstream · xstream · CWE-121 | High7.5 | — | 19.7% | Sep 16, 2022 |
36Monitor | CVE-2021-39139No exploit | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | High8.8 | — | 4.5% | Aug 23, 2021 |
35Monitor | CVE-2021-39149No exploit | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | High8.5 | — | 4.7% | Aug 23, 2021 |
35Monitor | CVE-2021-39154No exploit | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | High8.5 | — | 4.7% | Aug 23, 2021 |
35Monitor | CVE-2021-39151No exploit | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | High8.5 | — | 4.7% | Aug 23, 2021 |
- CVE-2021-3914493Now
XStream is vulnerable to a Remote Command Execution attack
HighCVSS 8.5KEVWeaponizedEPSS 98%xstream · xstreamAug 23, 2021
- CVE-2019-1017368This week
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw.
CriticalCVSS 9.8No exploitEPSS 95%xstream · xstreamJul 23, 2019
- CVE-2013-728564This week
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run
CriticalCVSS 9.8Proof of conceptEPSS 84%xstream · xstreamMay 15, 2019
- CVE-2021-2134662This week
XStream is vulnerable to an Arbitrary Code Execution attack
CriticalCVSS 9.8No exploitEPSS 76%xstream · xstreamMar 22, 2021
- CVE-2021-2134462This week
XStream is vulnerable to an Arbitrary Code Execution attack
CriticalCVSS 9.8No exploitEPSS 76%xstream · xstreamMar 22, 2021
- CVE-2020-2621761This week
Remote Code Execution in XStream
HighCVSS 8.8Proof of conceptEPSS 85%xstream · xstreamNov 16, 2020
- CVE-2021-2135161This week
XStream is vulnerable to an Arbitrary Code Execution attack
CriticalCVSS 9.1Proof of conceptEPSS 82%xstream · xstreamMar 22, 2021
- CVE-2021-2134561This week
XStream is vulnerable to a Remote Command Execution attack
CriticalCVSS 9.9Proof of conceptEPSS 72%xstream · xstreamMar 22, 2021
- CVE-2021-2950558Plan
XStream is vulnerable to a Remote Command Execution attack
HighCVSS 8.8Proof of conceptEPSS 77%xstream · xstreamMay 28, 2021
- CVE-2020-2625855Plan
Server-Side Forgery Request can be activated unmarshalling with XStream
HighCVSS 7.7Proof of conceptEPSS 82%xstream · xstreamDec 15, 2020
- CVE-2021-2134153Plan
XStream can cause a Denial of Service
HighCVSS 7.5Proof of conceptEPSS 78%xstream · xstreamMar 22, 2021
- CVE-2020-2625952Plan
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
MediumCVSS 6.8Proof of conceptEPSS 82%xstream · xstreamDec 15, 2020
- CVE-2021-2134251Plan
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or
CriticalCVSS 9.1No exploitEPSS 50%xstream · xstreamMar 22, 2021
- CVE-2021-2134948Plan
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or
HighCVSS 8.6Proof of conceptEPSS 47%xstream · xstreamMar 22, 2021
- CVE-2021-2134344Plan
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
HighCVSS 7.5No exploitEPSS 47%xstream · xstreamMar 22, 2021
- CVE-2021-2135044Plan
XStream is vulnerable to an Arbitrary Code Execution attack
CriticalCVSS 9.8No exploitEPSS 15%xstream · xstreamMar 22, 2021
- CVE-2021-2134743Plan
XStream is vulnerable to an Arbitrary Code Execution attack
CriticalCVSS 9.8No exploitEPSS 14%xstream · xstreamMar 22, 2021
- CVE-2021-3914139Monitor
XStream is vulnerable to an Arbitrary Code Execution attack
HighCVSS 8.5Proof of conceptEPSS 16%xstream · xstreamAug 23, 2021
- CVE-2021-3914638Monitor
XStream is vulnerable to an Arbitrary Code Execution attack
HighCVSS 8.5Proof of conceptEPSS 14%xstream · xstreamAug 23, 2021
- CVE-2021-3915237Monitor
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
HighCVSS 8.5Proof of conceptEPSS 11%xstream · xstreamAug 23, 2021
- CVE-2022-4015236Monitor
Stack Buffer Overflow in Woodstox
HighCVSS 7.5No exploitEPSS 20%xstream · xstreamSep 16, 2022
- CVE-2021-3913936Monitor
XStream is vulnerable to an Arbitrary Code Execution attack
HighCVSS 8.8No exploitEPSS 5%xstream · xstreamAug 23, 2021
- CVE-2021-3914935Monitor
XStream is vulnerable to an Arbitrary Code Execution attack
HighCVSS 8.5No exploitEPSS 5%xstream · xstreamAug 23, 2021
- CVE-2021-3915435Monitor
XStream is vulnerable to an Arbitrary Code Execution attack
HighCVSS 8.5No exploitEPSS 5%xstream · xstreamAug 23, 2021
- CVE-2021-3915135Monitor
XStream is vulnerable to an Arbitrary Code Execution attack
HighCVSS 8.5No exploitEPSS 5%xstream · xstreamAug 23, 2021