VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 41 of 156
  • CVE-2020-8441CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.05

    JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product.

  • CVE-2019-20477CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.05

    PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

  • CVE-2020-9006CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.09

    The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary…

  • CVE-2020-6959CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.02

    The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6…

  • CVE-2019-17076CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro server.

  • CVE-2014-1860CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.04

    Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

  • CVE-2019-18956CriDec 17, 2019
    risk 0.64cvss 9.8epss 0.06

    Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2, and 1.2 < 1.2.4, and Proxia PHR 1.0 < 1.0.30 and 1.1 < 1.1.2 allows remote code execution via untrusted Java deserialization. The…

  • CVE-2019-19826CriDec 16, 2019
    risk 0.64cvss 9.8epss 0.02

    The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code…

  • CVE-2014-3699CriDec 15, 2019
    risk 0.64cvss 9.8epss 0.02

    eDeploy has RCE via cPickle deserialization of untrusted data

  • CVE-2019-18316CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 1099/tcp. Please note that an…

  • CVE-2019-18283CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.05

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by sending specifically crafted objects to one…

  • CVE-2019-19230CriDec 9, 2019
    risk 0.64cvss 9.8epss 0.04

    An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.

  • CVE-2019-18364CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.

  • CVE-2019-12017CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.03

    A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login and ticket issuance. An attacker can use the 'class' property of the JSON request sent to the CLDB to influence the JSON library's…

  • CVE-2019-13116CriOct 16, 2019
    risk 0.64cvss 9.8epss 0.05

    The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections

  • CVE-2019-10202CriOct 1, 2019
    risk 0.64cvss 9.8epss 0.05

    A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by…

  • CVE-2019-9365CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.01

    In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-16755CriSep 26, 2019
    risk 0.64cvss 9.8epss 0.03

    BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions:…

  • CVE-2017-18605CriSep 10, 2019
    risk 0.64cvss 9.8epss 0.02

    The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.

  • CVE-2018-11569CriSep 5, 2019
    risk 0.64cvss 9.8epss 0.02

    Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.