VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 36 of 166
  • CVE-2023-26512CriJul 17, 2023
    risk 0.64cvss 9.8epss 0.01

    CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can…

  • CVE-2023-25770CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-34347CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    ​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.

  • CVE-2023-28323CriJul 1, 2023
    risk 0.64cvss 9.8epss 0.03

    A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine…

  • CVE-2023-35839CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.

  • CVE-2023-32031HigJun 14, 2023
    risk 0.64cvss 8.8epss 0.81

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-33496CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.

  • CVE-2023-20888HigJun 7, 2023
    risk 0.64cvss 8.8epss 0.82

    Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code…

  • CVE-2020-36727CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it…

  • CVE-2020-36726CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present…

  • CVE-2023-33963CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7. There are no known…

  • CVE-2023-27068CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.

  • CVE-2023-31890CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.

  • CVE-2023-30899CriMay 9, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2…

  • CVE-2023-30898CriMay 9, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2…

  • CVE-2023-1967CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.

  • CVE-2023-20853CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or…

  • CVE-2023-20852CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.

  • CVE-2021-28254CriApr 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

  • CVE-2023-29216CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.02

    In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote code execution. Versions of…