VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 37 of 166
  • CVE-2023-28500CriApr 6, 2023
    risk 0.64cvss 9.8epss 0.01

    A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a specific URL. Adobe LiveCycle ES4 version…

  • CVE-2020-29312CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was…

  • CVE-2023-28462CriMar 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load malicious code on the server once a JNDI…

  • CVE-2022-36978CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2022-36977CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2023-28667CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result…

  • CVE-2023-26779CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).

  • CVE-2022-37936CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Java deserialization vulnerability in Serviceguard Manager

  • CVE-2023-26326CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.04

    The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects…

  • CVE-2023-21707HigFeb 14, 2023
    risk 0.64cvss 8.8epss 0.82

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-45982CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2023-24162CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.

  • CVE-2022-46478CriJan 13, 2023
    risk 0.64cvss 9.8epss 0.01

    The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.

  • CVE-2022-41778CriJan 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon…

  • CVE-2021-32824CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.03

    Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers…

  • CVE-2021-38241CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.

  • CVE-2022-44351CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.

  • CVE-2022-44371CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).

  • CVE-2022-46366CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version…

  • CVE-2022-45136CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of…