VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 39 of 166
  • CVE-2020-23620CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.

  • CVE-2022-25767CriMay 1, 2022
    risk 0.64cvss 9.8epss 0.03

    All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

  • CVE-2022-29528CriApr 20, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.

  • CVE-2020-19229CriApr 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.

  • CVE-2021-33207CriApr 5, 2022
    risk 0.64cvss 9.8epss 0.02

    The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.

  • CVE-2021-45899CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.02

    SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.

  • CVE-2021-45687CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the raw-cpuid crate before 9.1.1 for Rust. If the serialize feature is used (which is not the the default), a Deserialize operation may lack sufficient validation, leading to memory corruption or a panic.

  • CVE-2021-44029CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption…

  • CVE-2021-36336CriDec 21, 2021
    risk 0.64cvss 9.8epss 0.02

    Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.

  • CVE-2021-24857CriDec 13, 2021
    risk 0.64cvss 9.8epss 0.02

    The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

  • CVE-2021-42125HigDec 7, 2021
    risk 0.64cvss 8.8epss 0.82

    An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.

  • CVE-2021-44682CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44681CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44680CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44679CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44678CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44677CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-36567CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.

  • CVE-2021-36564CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.

  • CVE-2021-40719CriOct 21, 2021
    risk 0.64cvss 9.8epss 0.04

    Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation when AMF messages are deserialized on an Adobe Connect server. An attacker can leverage this to execute remote code execution on the…