Записи xstream
37 опубликованных записей вендора xstream.
Профиль для исследователя
- Попали в KEV
- 1 · 2,7 %
- С эксплойтом
- 1 · 2,7 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- 564 дн.
Повторяющиеся классы
- CWE-434 Unrestricted Upload of File with Dangerous Type15
- CWE-502 Deserialization of Untrusted Data5
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-121 Stack-based Buffer Overflow2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
37 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
93Срочно | CVE-2021-39144Готовый эксплойт | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | Высокая8,5 | KEV | 98,1 % | 23 авг. 2021 г. |
68На этой неделе | CVE-2019-10173Эксплойта нет | It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw.xstream · xstream · CWE-94 | Критическая9,8 | — | 95,0 % | 23 июл. 2019 г. |
64На этой неделе | CVE-2013-7285Proof of concept | Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run xstream · xstream · CWE-78 | Критическая9,8 | — | 84,4 % | 15 мая 2019 г. |
62На этой неделе | CVE-2021-21346Эксплойта нет | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Критическая9,8 | — | 76,4 % | 22 мар. 2021 г. |
62На этой неделе | CVE-2021-21344Эксплойта нет | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Критическая9,8 | — | 76,0 % | 22 мар. 2021 г. |
61На этой неделе | CVE-2020-26217Proof of concept | Remote Code Execution in XStreamxstream · xstream · CWE-78 | Высокая8,8 | — | 85,0 % | 16 нояб. 2020 г. |
61На этой неделе | CVE-2021-21351Proof of concept | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Критическая9,1 | — | 82,1 % | 22 мар. 2021 г. |
61На этой неделе | CVE-2021-21345Proof of concept | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | Критическая9,9 | — | 72,3 % | 22 мар. 2021 г. |
58В плане | CVE-2021-29505Proof of concept | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | Высокая8,8 | — | 77,2 % | 28 мая 2021 г. |
55В плане | CVE-2020-26258Proof of concept | Server-Side Forgery Request can be activated unmarshalling with XStreamxstream · xstream · CWE-918 | Высокая7,7 | — | 81,8 % | 15 дек. 2020 г. |
53В плане | CVE-2021-21341Proof of concept | XStream can cause a Denial of Servicexstream · xstream · CWE-400 | Высокая7,5 | — | 77,8 % | 22 мар. 2021 г. |
52В плане | CVE-2020-26259Proof of concept | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshallingxstream · xstream · CWE-78 | Средняя6,8 | — | 82,4 % | 15 дек. 2020 г. |
51В плане | CVE-2021-21342Эксплойта нет | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or xstream · xstream · CWE-502 | Критическая9,1 | — | 50,0 % | 22 мар. 2021 г. |
48В плане | CVE-2021-21349Proof of concept | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or xstream · xstream · CWE-502 | Высокая8,6 | — | 46,8 % | 22 мар. 2021 г. |
44В плане | CVE-2021-21343Эксплойта нет | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rightsxstream · xstream · CWE-73 | Высокая7,5 | — | 46,7 % | 22 мар. 2021 г. |
44В плане | CVE-2021-21350Эксплойта нет | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Критическая9,8 | — | 15,2 % | 22 мар. 2021 г. |
43В плане | CVE-2021-21347Эксплойта нет | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Критическая9,8 | — | 14,3 % | 22 мар. 2021 г. |
39Наблюдать | CVE-2021-39141Proof of concept | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Высокая8,5 | — | 16,1 % | 23 авг. 2021 г. |
38Наблюдать | CVE-2021-39146Proof of concept | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Высокая8,5 | — | 14,3 % | 23 авг. 2021 г. |
37Наблюдать | CVE-2021-39152Proof of concept | A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshalingxstream · xstream · CWE-502 | Высокая8,5 | — | 11,4 % | 23 авг. 2021 г. |
36Наблюдать | CVE-2022-40152Эксплойта нет | Stack Buffer Overflow in Woodstoxxstream · xstream · CWE-121 | Высокая7,5 | — | 19,7 % | 16 сент. 2022 г. |
36Наблюдать | CVE-2021-39139Эксплойта нет | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Высокая8,8 | — | 4,5 % | 23 авг. 2021 г. |
35Наблюдать | CVE-2021-39149Эксплойта нет | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Высокая8,5 | — | 4,7 % | 23 авг. 2021 г. |
35Наблюдать | CVE-2021-39154Эксплойта нет | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Высокая8,5 | — | 4,7 % | 23 авг. 2021 г. |
35Наблюдать | CVE-2021-39151Эксплойта нет | XStream is vulnerable to an Arbitrary Code Execution attackxstream · xstream · CWE-434 | Высокая8,5 | — | 4,7 % | 23 авг. 2021 г. |
- CVE-2021-3914493Срочно
XStream is vulnerable to a Remote Command Execution attack
ВысокаяCVSS 8,5KEVГотовый эксплойтEPSS 98 %xstream · xstream23 авг. 2021 г.
- CVE-2019-1017368На этой неделе
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw.
КритическаяCVSS 9,8Эксплойта нетEPSS 95 %xstream · xstream23 июл. 2019 г.
- CVE-2013-728564На этой неделе
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run
КритическаяCVSS 9,8Proof of conceptEPSS 84 %xstream · xstream15 мая 2019 г.
- CVE-2021-2134662На этой неделе
XStream is vulnerable to an Arbitrary Code Execution attack
КритическаяCVSS 9,8Эксплойта нетEPSS 76 %xstream · xstream22 мар. 2021 г.
- CVE-2021-2134462На этой неделе
XStream is vulnerable to an Arbitrary Code Execution attack
КритическаяCVSS 9,8Эксплойта нетEPSS 76 %xstream · xstream22 мар. 2021 г.
- CVE-2020-2621761На этой неделе
Remote Code Execution in XStream
ВысокаяCVSS 8,8Proof of conceptEPSS 85 %xstream · xstream16 нояб. 2020 г.
- CVE-2021-2135161На этой неделе
XStream is vulnerable to an Arbitrary Code Execution attack
КритическаяCVSS 9,1Proof of conceptEPSS 82 %xstream · xstream22 мар. 2021 г.
- CVE-2021-2134561На этой неделе
XStream is vulnerable to a Remote Command Execution attack
КритическаяCVSS 9,9Proof of conceptEPSS 72 %xstream · xstream22 мар. 2021 г.
- CVE-2021-2950558В плане
XStream is vulnerable to a Remote Command Execution attack
ВысокаяCVSS 8,8Proof of conceptEPSS 77 %xstream · xstream28 мая 2021 г.
- CVE-2020-2625855В плане
Server-Side Forgery Request can be activated unmarshalling with XStream
ВысокаяCVSS 7,7Proof of conceptEPSS 82 %xstream · xstream15 дек. 2020 г.
- CVE-2021-2134153В плане
XStream can cause a Denial of Service
ВысокаяCVSS 7,5Proof of conceptEPSS 78 %xstream · xstream22 мар. 2021 г.
- CVE-2020-2625952В плане
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
СредняяCVSS 6,8Proof of conceptEPSS 82 %xstream · xstream15 дек. 2020 г.
- CVE-2021-2134251В плане
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or
КритическаяCVSS 9,1Эксплойта нетEPSS 50 %xstream · xstream22 мар. 2021 г.
- CVE-2021-2134948В плане
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or
ВысокаяCVSS 8,6Proof of conceptEPSS 47 %xstream · xstream22 мар. 2021 г.
- CVE-2021-2134344В плане
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
ВысокаяCVSS 7,5Эксплойта нетEPSS 47 %xstream · xstream22 мар. 2021 г.
- CVE-2021-2135044В плане
XStream is vulnerable to an Arbitrary Code Execution attack
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %xstream · xstream22 мар. 2021 г.
- CVE-2021-2134743В плане
XStream is vulnerable to an Arbitrary Code Execution attack
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %xstream · xstream22 мар. 2021 г.
- CVE-2021-3914139Наблюдать
XStream is vulnerable to an Arbitrary Code Execution attack
ВысокаяCVSS 8,5Proof of conceptEPSS 16 %xstream · xstream23 авг. 2021 г.
- CVE-2021-3914638Наблюдать
XStream is vulnerable to an Arbitrary Code Execution attack
ВысокаяCVSS 8,5Proof of conceptEPSS 14 %xstream · xstream23 авг. 2021 г.
- CVE-2021-3915237Наблюдать
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
ВысокаяCVSS 8,5Proof of conceptEPSS 11 %xstream · xstream23 авг. 2021 г.
- CVE-2022-4015236Наблюдать
Stack Buffer Overflow in Woodstox
ВысокаяCVSS 7,5Эксплойта нетEPSS 20 %xstream · xstream16 сент. 2022 г.
- CVE-2021-3913936Наблюдать
XStream is vulnerable to an Arbitrary Code Execution attack
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %xstream · xstream23 авг. 2021 г.
- CVE-2021-3914935Наблюдать
XStream is vulnerable to an Arbitrary Code Execution attack
ВысокаяCVSS 8,5Эксплойта нетEPSS 5 %xstream · xstream23 авг. 2021 г.
- CVE-2021-3915435Наблюдать
XStream is vulnerable to an Arbitrary Code Execution attack
ВысокаяCVSS 8,5Эксплойта нетEPSS 5 %xstream · xstream23 авг. 2021 г.
- CVE-2021-3915135Наблюдать
XStream is vulnerable to an Arbitrary Code Execution attack
ВысокаяCVSS 8,5Эксплойта нетEPSS 5 %xstream · xstream23 авг. 2021 г.