CVE-2016-3674

🟡 Monitoruj

Wielokrotne podatności XXE w XStream umożliwiają zdalne odczytywanie plików.

CVSS
7.5
EPSS
8.2%
Exploit
none
Vendor
fedoraproject
Opis źródłowy (NVD)

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

xxe Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)8.2%
Opublikowano (NVD)2016-05-17 14:08:03 UTC
Ostatnia modyfikacja (NVD)2026-10-08 21:17:05 UTC
Referencje