VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 167 of 167
  • CVE-2010-4574Dec 22, 2010
    risk 0.00cvss —epss 0.02

    The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization validation, and cause a…

  • CVE-2010-3258Sep 7, 2010
    risk 0.00cvss —epss 0.01

    The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attack vectors.

  • CVE-2005-2875Sep 13, 2005
    risk 0.00cvss —epss 0.02

    Py2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes.