Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-3674
Description:Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Test IDs: 1.3.6.1.4.1.25623.1.0.807751   1.3.6.1.4.1.25623.1.1.1.2.2016.504   1.3.6.1.4.1.25623.1.0.703575   1.3.6.1.4.1.25623.1.0.807953   1.3.6.1.4.1.25623.1.0.131288  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-3674
BugTraq ID: 85381
http://www.securityfocus.com/bid/85381
Debian Security Information: DSA-3575 (Google Search)
http://www.debian.org/security/2016/dsa-3575
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183208.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183180.html
http://www.openwall.com/lists/oss-security/2016/03/25/8
http://www.openwall.com/lists/oss-security/2016/03/28/1
RedHat Security Advisories: RHSA-2016:2822
http://rhn.redhat.com/errata/RHSA-2016-2822.html
RedHat Security Advisories: RHSA-2016:2823
http://rhn.redhat.com/errata/RHSA-2016-2823.html
http://www.securitytracker.com/id/1036419




© 1998-2025 E-Soft Inc. All rights reserved.