CVE-2022-40151

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.84 % (82th)
0.84% Progress
Affected Products 1
Advisories 4

Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

Weaknesses
CWE-121
Stack-based Buffer Overflow
CWE-787
Out-of-bounds Write
CVE Status
PUBLISHED
CNA
Google Inc.
Published Date
2022-09-16 10:15:09
(2 years ago)
Updated Date
2022-09-20 18:11:31
(2 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Xstream Project Xstream 1.4.19 and prior versions cpe:2.3:a:xstream_project:xstream <= 1.4.19
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...