CVE-2021-39144
- EPSS 94.38%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 24.10.2025 14:47:35
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user...
CVE-2021-39145
- EPSS 0.5%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:52:04
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39146
- EPSS 54.18%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:48:45
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39147
- EPSS 0.57%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:51:54
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39148
- EPSS 0.57%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:48:30
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39149
- EPSS 0.71%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:50:01
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39151
- EPSS 0.57%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:49:36
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39139
- EPSS 0.84%
- Veröffentlicht 23.08.2021 18:15:10
- Zuletzt bearbeitet 23.05.2025 16:52:49
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user ...
CVE-2021-3731
- EPSS 0.15%
- Veröffentlicht 23.08.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:16
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
CVE-2021-3693
- EPSS 0.79%
- Veröffentlicht 23.08.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:10
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.