Debian Libxstream-Java vulnerabilities
36 known vulnerabilities affecting debian/libxstream-java.
Total CVEs
36
CISA KEV
1
actively exploited
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH21MEDIUM13
Vulnerabilities
Page 2 of 2
CVE-2021-39139P2HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39139 [HIGH] CVE-2021-39139: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21 or below. However, this scenario can be a
debian
CVE-2021-39149P2HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39149 [HIGH] CVE-2021-39149: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39151P2HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39151 [HIGH] CVE-2021-39151: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39154P2HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39154 [HIGH] CVE-2021-39154: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39148P2HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39148 [HIGH] CVE-2021-39148: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39147P2HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39147 [HIGH] CVE-2021-39147: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39153P3HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39153 [HIGH] CVE-2021-39153: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or with JavaFX installed. No user is affected,
debian
CVE-2021-39145P3HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39145 [HIGH] CVE-2021-39145: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
debian
CVE-2021-39150P3HIGHCVSS 8.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39150 [HIGH] CVE-2021-39150: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup X
debian
CVE-2021-21348P3MEDIUMCVSS 5.3fixed in libxstream-java 1.4.15-2 (bookworm)2021
CVE-2021-21348 [MEDIUM] CVE-2021-21348: libxstream-java - XStream is a Java library to serialize objects to XML and back again. In XStream...
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the
debian
CVE-2016-3674P3HIGHCVSS 7.5fixed in libxstream-java 1.4.9-1 (bookworm)2016
CVE-2016-3674 [HIGH] CVE-2016-3674: libxstream-java - Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) D...
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Scope: local
bookworm: resolved (fixed in 1.4.9-1)
bullseye: resolved (f
debian
CVE-2021-43859P3HIGHCVSS 7.5fixed in libxstream-java 1.4.19-1 (bookworm)2021
CVE-2021-43859 [HIGH] CVE-2021-43859: libxstream-java - XStream is an open source java library to serialize objects to XML and back agai...
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accum
debian
CVE-2022-41966P3HIGHCVSS 8.2fixed in libxstream-java 1.4.20-1 (bookworm)2022
CVE-2022-41966 [HIGH] CVE-2022-41966: libxstream-java - XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 ...
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causi
debian
CVE-2024-47072P3HIGHCVSS 7.5fixed in libxstream-java 1.4.20-1+deb12u1 (bookworm)2024
CVE-2024-47072 [HIGH] CVE-2024-47072: libxstream-java - XStream is a simple library to serialize objects to XML and back again. This vul...
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the
debian
CVE-2021-39140P3MEDIUMCVSS 6.5fixed in libxstream-java 1.4.18-1 (bookworm)2021
CVE-2021-39140 [MEDIUM] CVE-2021-39140: libxstream-java - XStream is a simple library to serialize objects to XML and back again. In affec...
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected, who fo
debian
CVE-2017-7957P3HIGHCVSS 7.5fixed in libxstream-java 1.4.9-2 (bookworm)2017
CVE-2017-7957 [HIGH] CVE-2017-7957: libxstream-java - XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandl...
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
Scope: local
bookworm: resolved (fixed in 1.4.9-2)
bullseye: resolved (fixed in 1.4.9-2)
forky: resolved (fixe
debian
← Previous2 / 2