CVE-2016-3674 PUBLISHED

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.

EPSS 2.86% · 86.1th percentile

Risk Scores

EPSS Score
2.86%
86.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlibxstream-java1.4.8-1ubuntu0.1+esm2, 0, 1.4.8-1
Ubuntu:Pro:14.04:LTSlibxstream-java0, 1.4.4-1, 1.4.7-1

Timeline

References

Open in Interactive Console →