CVE-2021-39145
- EPSS 4.07%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:52:04
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39146
- EPSS 14.3%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:48:45
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39147
- EPSS 4.74%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:51:54
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39148
- EPSS 4.74%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:48:30
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39149
- EPSS 4.74%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:50:01
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39151
- EPSS 4.74%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:49:36
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39139
- EPSS 4.54%
- Veröffentlicht 23.08.2021 18:15:10
- Zuletzt bearbeitet 23.05.2025 16:52:49
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user ...
CVE-2021-37714
- EPSS 6.87%
- Veröffentlicht 18.08.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:46
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the par...
CVE-2021-35516
- EPSS 12.37%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:25
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services tha...
CVE-2021-35517
- EPSS 10.61%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:25
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services th...