CVE-2016-3674: Debian Linux
High severity, CVSS 7.5. EPSS: 8.2% chance of exploitation in the next 30 days.
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Affected products
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 22 only; version 23 only
- Red Hat JBoss Middleware: version 1 only
- XStream XStream: before 1.4.9 (fixed in 1.4.9)
Published 2016-05-17. Last modified 2026-10-08.