CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,116)
page 105 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1405 | Hig | 0.49 | 7.5 | 0.01 | Jan 16, 2024 | The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present. | ||
| CVE-2023-32513 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2023 | Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3. | ||
| CVE-2023-49819 | Hig | 0.49 | 7.5 | 0.01 | Dec 19, 2023 | Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3. | ||
| CVE-2023-48952 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2023 | An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | ||
| CVE-2023-45672 | Hig | 0.49 | 7.5 | 0.01 | Oct 30, 2023 | Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerability was identified in the endpoints used to save configurations for Frigate. This can lead to unauthenticated remote code execution. This can be performed… | ||
| CVE-2023-39680 | Hig | 0.49 | 7.5 | 0.01 | Oct 20, 2023 | Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code. | ||
| CVE-2023-4528 | Hig | 0.49 | 7.2 | 0.27 | Sep 7, 2023 | Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface | ||
| CVE-2023-39396 | Hig | 0.49 | 7.5 | 0.01 | Aug 13, 2023 | Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-24971 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2023 | IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976. | ||
| CVE-2023-26548 | Hig | 0.49 | 7.5 | 0.01 | Mar 27, 2023 | The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-26464 | Hig | 0.49 | 7.5 | 0.02 | Mar 10, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging… | ||
| CVE-2022-47504 | Hig | 0.49 | 7.2 | 0.25 | Feb 15, 2023 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2022-47503 | Hig | 0.49 | 7.2 | 0.24 | Feb 15, 2023 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2022-31710 | Hig | 0.49 | 7.5 | 0.01 | Jan 26, 2023 | vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service. | ||
| CVE-2023-21538 | Hig | 0.49 | 7.5 | 0.03 | Jan 10, 2023 | .NET Denial of Service Vulnerability | ||
| CVE-2022-41596 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components. | ||
| CVE-2022-0138 | Hig | 0.49 | 7.5 | 0.01 | Feb 18, 2022 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has a deserialization function that does not validate or check the data, allowing arbitrary classes to be created. | ||
| CVE-2021-26558 | Hig | 0.49 | 7.5 | 0.02 | Nov 11, 2021 | Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versions prior to 5.0.0. | ||
| CVE-2021-32836 | Hig | 0.49 | 7.5 | 0.02 | Sep 9, 2021 | ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST API. An attacker in control of the request body will be able to provide both the class name and the… | ||
| CVE-2021-32742 | Hig | 0.49 | 7.5 | 0.01 | Jul 9, 2021 | Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens up the potential for exposing server memory and/or crashing the server (Denial of Service) for applications where untrusted data can end up in said function.… |
- risk 0.49cvss 7.5epss 0.01
The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
- risk 0.49cvss 7.5epss 0.01
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.
- risk 0.49cvss 7.5epss 0.01
Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3.
- risk 0.49cvss 7.5epss 0.01
An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
- risk 0.49cvss 7.5epss 0.01
Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerability was identified in the endpoints used to save configurations for Frigate. This can lead to unauthenticated remote code execution. This can be performed…
- risk 0.49cvss 7.5epss 0.01
Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code.
- risk 0.49cvss 7.2epss 0.27
Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
- risk 0.49cvss 7.5epss 0.01
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.01
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.
- risk 0.49cvss 7.5epss 0.01
The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.02
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging…
- risk 0.49cvss 7.2epss 0.25
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.49cvss 7.2epss 0.24
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.49cvss 7.5epss 0.01
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
- risk 0.49cvss 7.5epss 0.03
.NET Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.00
The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.
- risk 0.49cvss 7.5epss 0.01
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has a deserialization function that does not validate or check the data, allowing arbitrary classes to be created.
- risk 0.49cvss 7.5epss 0.02
Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versions prior to 5.0.0.
- risk 0.49cvss 7.5epss 0.02
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST API. An attacker in control of the request body will be able to provide both the class name and the…
- risk 0.49cvss 7.5epss 0.01
Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens up the potential for exposing server memory and/or crashing the server (Denial of Service) for applications where untrusted data can end up in said function.…