Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Xstream
HIGH 7.5
CVE-2022-41966EPSS 9%
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack…
Fix: 1.4.20+
Fix from $1,950
2022-12-28
Xstream
HIGH 7.5
CVE-2022-40151
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an at…
Fix: 1.4.20+
Fix from $1,950
2022-09-16
Xstream
HIGH 7.5
CVE-2022-40152EPSS 20%
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on us…
Fix: 1.4.20 / 5.4.0+
Fix from $1,950
2022-09-16
Xstream
CRITICAL 9.8
CVE-2019-10173EPSS 95%
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has…
Fix: after 8.2.2
Fix from $2,300
2019-07-23