Логотип exploitDog
bind:"CVE-2024-47072"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-47072"

Количество 8

Количество 8

ubuntu логотип

CVE-2024-47072

около 1 года назад

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-47072

около 1 года назад

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-47072

около 1 года назад

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-47072

около 1 года назад

XStream is a simple library to serialize objects to XML and back again ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4037-1

около 1 года назад

Security update for bea-stax, xstream

EPSS: Низкий
github логотип

GHSA-hfq9-hggm-c56q

около 1 года назад

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-09422

около 1 года назад

Уязвимость компонента BinaryStreamDriver Java-библиотеки для преобразования объектов в XML или JSON формат XStream, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании»

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250821-02

5 месяцев назад

Уязвимость xstream

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-47072

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.

CVSS3: 7.5
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-47072

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.

CVSS3: 7.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-47072

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.

CVSS3: 7.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-47072

XStream is a simple library to serialize objects to XML and back again ...

CVSS3: 7.5
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4037-1

Security update for bea-stax, xstream

0%
Низкий
около 1 года назад
github логотип
GHSA-hfq9-hggm-c56q

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

CVSS3: 7.5
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-09422

Уязвимость компонента BinaryStreamDriver Java-библиотеки для преобразования объектов в XML или JSON формат XStream, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании»

CVSS3: 7.5
0%
Низкий
около 1 года назад
redos логотип
ROS-20250821-02

Уязвимость xstream

CVSS3: 7.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу