VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 105 of 156
  • CVE-2023-1405HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

  • CVE-2023-32513HigDec 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.

  • CVE-2023-49819HigDec 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3.

  • CVE-2023-48952HigNov 29, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.

  • CVE-2023-45672HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerability was identified in the endpoints used to save configurations for Frigate. This can lead to unauthenticated remote code execution. This can be performed…

  • CVE-2023-39680HigOct 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code.

  • CVE-2023-4528HigSep 7, 2023
    risk 0.49cvss 7.2epss 0.27

    Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface

  • CVE-2023-39396HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-24971HigJul 31, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.

  • CVE-2023-26548HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.01

    The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-26464HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.02

    ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging…

  • CVE-2022-47504HigFeb 15, 2023
    risk 0.49cvss 7.2epss 0.25

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-47503HigFeb 15, 2023
    risk 0.49cvss 7.2epss 0.24

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-31710HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.

  • CVE-2023-21538HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.03

    .NET Denial of Service Vulnerability

  • CVE-2022-41596HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.

  • CVE-2022-0138HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.01

    MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has a deserialization function that does not validate or check the data, allowing arbitrary classes to be created.

  • CVE-2021-26558HigNov 11, 2021
    risk 0.49cvss 7.5epss 0.02

    Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versions prior to 5.0.0.

  • CVE-2021-32836HigSep 9, 2021
    risk 0.49cvss 7.5epss 0.02

    ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST API. An attacker in control of the request body will be able to provide both the class name and the…

  • CVE-2021-32742HigJul 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens up the potential for exposing server memory and/or crashing the server (Denial of Service) for applications where untrusted data can end up in said function.…