cbcvebase.

Debian Libxstream-Java vulnerabilities

37 known vulnerabilities affecting debian/libxstream-java.

Total CVEs
37
CISA KEV
1
actively exploited
Public exploits
10
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH21MEDIUM13LOW1

Vulnerabilities

Page 1 of 2
CVE-2024-47072HIGHCVSS 7.5fixed in libxstream-java 1.4.20-1+deb12u1 (bookworm)2024
CVE-2024-47072 [HIGH] CVE-2024-47072: libxstream-java - XStream is a simple library to serialize objects to XML and back again. This vul... XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the
debian
CVE-2022-41966HIGHCVSS 8.2fixed in libxstream-java 1.4.20-1 (bookworm)2022
CVE-2022-41966 [HIGH] CVE-2022-41966: libxstream-java - XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 ... XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causi
debian
CVE-2022-40151LOWCVSS 6.52022
CVE-2022-40151 [MEDIUM] CVE-2022-40151: libxstream-java - Those using Xstream to seralize XML data may be vulnerable to Denial of Service ... Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2021-39139HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39139 [HIGH] CVE-2021-39139: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21 or below. However, this scenario can be a
debian
CVE-2021-39144HIGHCVSS 8.5KEVPoCfixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39144 [HIGH] CVE-2021-39144: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39149HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39149 [HIGH] CVE-2021-39149: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39150HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39150 [HIGH] CVE-2021-39150: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup X
debian
CVE-2021-39151HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39151 [HIGH] CVE-2021-39151: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39141HIGHCVSS 8.5PoCfixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39141 [HIGH] CVE-2021-39141: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39153HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39153 [HIGH] CVE-2021-39153: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or with JavaFX installed. No user is affected,
debian
CVE-2021-43859HIGHCVSS 7.5fixed in libxstream-java 1.4.19-1 (bookworm)2021
CVE-2021-43859 [HIGH] CVE-2021-43859: libxstream-java - XStream is an open source java library to serialize objects to XML and back agai... XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accum
debian
CVE-2021-39146HIGHCVSS 8.5PoCfixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39146 [HIGH] CVE-2021-39146: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39154HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39154 [HIGH] CVE-2021-39154: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-21341HIGHCVSS 7.5fixed in libxstream-java 1.4.15-2 (bookworm)2021
CVE-2021-21341 [HIGH] CVE-2021-21341: libxstream-java - XStream is a Java library to serialize objects to XML and back again. In XStream... XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user
debian
CVE-2021-29505HIGHCVSS 7.5PoCfixed in libxstream-java 1.4.15-3 (bookworm)2021
CVE-2021-29505 [HIGH] CVE-2021-29505: libxstream-java - XStream is software for serializing Java objects to XML and back again. A vulner... XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to
debian
CVE-2021-39145HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39145 [HIGH] CVE-2021-39145: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39148HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39148 [HIGH] CVE-2021-39148: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39152HIGHCVSS 8.5PoCfixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39152 [HIGH] CVE-2021-39152: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup X
debian
CVE-2021-39147HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39147 [HIGH] CVE-2021-39147: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec... XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-21348MEDIUMCVSS 5.3fixed in libxstream-java 1.4.15-2 (bookworm)2021
CVE-2021-21348 [MEDIUM] CVE-2021-21348: libxstream-java - XStream is a Java library to serialize objects to XML and back again. In XStream... XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the
debian