VYPR

rpm package

suse/xstream&distro=SUSE Manager Server Module 4.2

pkg:rpm/suse/xstream&distro=SUSE%20Manager%20Server%20Module%204.2

Vulnerabilities (29)

  • CVE-2022-41966Dec 27, 2022
    affected < 1.4.20-150200.3.25.1fixed 1.4.20-150200.3.25.1

    XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code i

  • CVE-2022-40151Sep 16, 2022
    affected < 1.4.20-150200.3.25.1fixed 1.4.20-150200.3.25.1

    Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

  • CVE-2021-43859Feb 1, 2022
    affected < 1.4.19-3.18.2fixed 1.4.19-3.18.2

    XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service on

  • CVE-2021-39150Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime

  • CVE-2021-39152Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime

  • CVE-2021-39140Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of servic

  • CVE-2021-39149Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39148Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39147Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39146Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39145Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39141Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39153Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box w

  • CVE-2021-39151Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39139Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the

  • CVE-2021-39154Aug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-39144KEVAug 23, 2021
    affected < 1.4.18-3.14.1fixed 1.4.18-3.14.1

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the

  • CVE-2021-29505May 28, 2021
    affected < 1.4.17-3.11.2fixed 1.4.17-3.11.2

    XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the

  • CVE-2021-21348Mar 22, 2021
    affected < 1.4.16-3.8.1fixed 1.4.16-3.8.1

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recomm

  • CVE-2021-21349Mar 22, 2021
    affected < 1.4.16-3.8.1fixed 1.4.16-3.8.1

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stre

Page 1 of 2