VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 136 of 156
  • CVE-2024-39630MedAug 1, 2024
    risk 0.36cvss 5.5epss 0.00

    Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.

  • CVE-2024-0047MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction…

  • CVE-2024-1750MedFeb 22, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library lib/images_get_down.php of the component Image Download Handler. The manipulation leads to deserialization. It is possible to…

  • CVE-2022-47599MedDec 20, 2023
    risk 0.36cvss 5.5epss 0.01

    Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File…

  • CVE-2023-40121MedOct 27, 2023
    risk 0.36cvss 5.5epss 0.00

    In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-32665MedSep 14, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.

  • CVE-2023-21205MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-3308MedJun 18, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of the component Aviator Template Engine. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. The identifier of…

  • CVE-2022-48282MedFeb 21, 2023
    risk 0.36cvss 6.6epss 0.01

    Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which may cause further disruption to services. This is specific to applications written in C#. This affects all MongoDB .NET/C# Driver…

  • CVE-2022-21663MedJan 6, 2022
    risk 0.36cvss 6.6epss 0.04

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in…

  • CVE-2021-42550MedDec 16, 2021
    risk 0.36cvss 6.6epss 0.04

    In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

  • CVE-2021-21350MedMar 23, 2021
    risk 0.36cvss 5.3epss 0.15

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the…

  • CVE-2021-21348MedMar 23, 2021
    risk 0.36cvss 5.3epss 0.14

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the…

  • CVE-2020-0132MedJun 11, 2020
    risk 0.36cvss 5.5epss 0.00

    In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-9373MedSep 27, 2019
    risk 0.36cvss 5.5epss 0.00

    In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:…

  • CVE-2026-59242MedAug 12, 2026
    risk 0.35cvss 5.4epss 0.01

    Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to…

  • CVE-2026-56304MedJun 20, 2026
    risk 0.35cvss 6.5epss 0.00

    picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Attackers can exploit this by crafting malicious pickle payloads to bypass RCE…

  • CVE-2026-48560MedJun 9, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-34993MedJun 2, 2026
    risk 0.35cvss 6.4epss 0.00

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this…

  • CVE-2026-2265MedApr 1, 2026
    risk 0.35cvss 6.5epss 0.00

    An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.