CVE-2016-3674

Source
https://cve.org/CVERecord?id=CVE-2016-3674
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3674.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-3674
Aliases
Downstream
Related
Published
2016-05-17T14:08:03.607Z
Modified
2026-02-05T11:01:30.643276Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

References

Affected packages

Git / github.com/x-stream/xstream

Affected ranges

Type
GIT
Repo
https://github.com/x-stream/xstream
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other
XSTREAM_1_4_5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3674.json"