VYPR

Maven package

com.thoughtworks.xstream/xstream

pkg:maven/com.thoughtworks.xstream/xstream

Vulnerabilities (37)

  • CVE-2024-47072HigNov 8, 2024
    affected < 1.4.21fixed 1.4.21

    XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configu

  • CVE-2022-41966HigDec 28, 2022
    affected < 1.4.20fixed 1.4.20

    XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code i

  • CVE-2022-40151MedSep 16, 2022
    affected < 1.4.20fixed 1.4.20

    Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

  • CVE-2021-43859HigFeb 1, 2022
    affected < 1.4.19fixed 1.4.19

    XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service on

  • CVE-2021-39152HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime

  • CVE-2021-39150HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime

  • CVE-2021-39140MedAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of servic

  • CVE-2021-39154HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39153HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box w

  • CVE-2021-39151HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39149HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39148HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39147HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39146HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39145HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39144HigKEVAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39141HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39139HigAug 23, 2021
    affected < 1.4.18fixed 1.4.18

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the

  • CVE-2021-29505HigMay 28, 2021
    affected < 1.4.17fixed 1.4.17

    XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the

  • CVE-2021-21351MedMar 23, 2021
    affected < 1.4.16fixed 1.4.16

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected,

Page 1 of 2