VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 102 of 167
  • CVE-2022-33316HigJul 20, 2022
    risk 0.51cvss 7.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics…

  • CVE-2022-33315HigJul 20, 2022
    risk 0.51cvss 7.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics…

  • CVE-2022-27580HigJul 19, 2022
    risk 0.51cvss 7.8epss 0.00

    A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code…

  • CVE-2022-27579HigJul 19, 2022
    risk 0.51cvss 7.8epss 0.00

    A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute…

  • CVE-2021-36665HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

  • CVE-2021-33036HigJun 15, 2022
    risk 0.51cvss 8.8epss 0.04

    In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

  • CVE-2021-21956HigApr 14, 2022
    risk 0.51cvss 7.8epss 0.01

    A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-26503HigMar 17, 2022
    risk 0.51cvss 7.8epss 0.01

    Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.

  • CVE-2021-46364HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

  • CVE-2021-0970HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-42698HigNov 5, 2021
    risk 0.51cvss 7.8epss 0.01

    Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory.

  • CVE-2021-41078HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.02

    Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.

  • CVE-2021-0685HigOct 6, 2021
    risk 0.51cvss 7.8epss 0.00

    In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-32568HigSep 6, 2021
    risk 0.51cvss 7.8epss 0.01

    mrdoc is vulnerable to Deserialization of Untrusted Data

  • CVE-2021-21869HigAug 25, 2021
    risk 0.51cvss 7.8epss 0.02

    An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious…

  • CVE-2021-21868HigAug 18, 2021
    risk 0.51cvss 7.8epss 0.02

    An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious…

  • CVE-2021-21867HigAug 18, 2021
    risk 0.51cvss 7.8epss 0.02

    An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a…

  • CVE-2021-21863HigAug 5, 2021
    risk 0.51cvss 7.8epss 0.01

    A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to…

  • CVE-2021-21866HigAug 2, 2021
    risk 0.51cvss 7.8epss 0.02

    A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a…

  • CVE-2021-21865HigAug 2, 2021
    risk 0.51cvss 7.8epss 0.01

    A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to…