CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,116)
page 41 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8441 | Cri | 0.64 | 9.8 | 0.05 | Feb 19, 2020 | JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product. | ||
| CVE-2019-20477 | Cri | 0.64 | 9.8 | 0.05 | Feb 19, 2020 | PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342. | ||
| CVE-2020-9006 | Cri | 0.64 | 9.8 | 0.09 | Feb 17, 2020 | The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary… | ||
| CVE-2020-6959 | Cri | 0.64 | 9.8 | 0.02 | Jan 22, 2020 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6… | ||
| CVE-2019-17076 | Cri | 0.64 | 9.8 | 0.03 | Jan 8, 2020 | An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro server. | ||
| CVE-2014-1860 | Cri | 0.64 | 9.8 | 0.04 | Jan 8, 2020 | Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities | ||
| CVE-2019-18956 | Cri | 0.64 | 9.8 | 0.06 | Dec 17, 2019 | Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2, and 1.2 < 1.2.4, and Proxia PHR 1.0 < 1.0.30 and 1.1 < 1.1.2 allows remote code execution via untrusted Java deserialization. The… | ||
| CVE-2019-19826 | Cri | 0.64 | 9.8 | 0.02 | Dec 16, 2019 | The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code… | ||
| CVE-2014-3699 | Cri | 0.64 | 9.8 | 0.02 | Dec 15, 2019 | eDeploy has RCE via cPickle deserialization of untrusted data | ||
| CVE-2019-18316 | Cri | 0.64 | 9.8 | 0.03 | Dec 12, 2019 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 1099/tcp. Please note that an… | ||
| CVE-2019-18283 | Cri | 0.64 | 9.8 | 0.05 | Dec 12, 2019 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by sending specifically crafted objects to one… | ||
| CVE-2019-19230 | Cri | 0.64 | 9.8 | 0.04 | Dec 9, 2019 | An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code. | ||
| CVE-2019-18364 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. | ||
| CVE-2019-12017 | Cri | 0.64 | 9.8 | 0.03 | Oct 24, 2019 | A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login and ticket issuance. An attacker can use the 'class' property of the JSON request sent to the CLDB to influence the JSON library's… | ||
| CVE-2019-13116 | Cri | 0.64 | 9.8 | 0.05 | Oct 16, 2019 | The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections | ||
| CVE-2019-10202 | Cri | 0.64 | 9.8 | 0.05 | Oct 1, 2019 | A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by… | ||
| CVE-2019-9365 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2019 | In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID:… | ||
| CVE-2019-16755 | Cri | 0.64 | 9.8 | 0.03 | Sep 26, 2019 | BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions:… | ||
| CVE-2017-18605 | Cri | 0.64 | 9.8 | 0.02 | Sep 10, 2019 | The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. | ||
| CVE-2018-11569 | Cri | 0.64 | 9.8 | 0.02 | Sep 5, 2019 | Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2. |
- risk 0.64cvss 9.8epss 0.05
JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product.
- risk 0.64cvss 9.8epss 0.05
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
- risk 0.64cvss 9.8epss 0.09
The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary…
- risk 0.64cvss 9.8epss 0.02
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro server.
- risk 0.64cvss 9.8epss 0.04
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
- risk 0.64cvss 9.8epss 0.06
Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2, and 1.2 < 1.2.4, and Proxia PHR 1.0 < 1.0.30 and 1.1 < 1.1.2 allows remote code execution via untrusted Java deserialization. The…
- risk 0.64cvss 9.8epss 0.02
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code…
- risk 0.64cvss 9.8epss 0.02
eDeploy has RCE via cPickle deserialization of untrusted data
- risk 0.64cvss 9.8epss 0.03
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 1099/tcp. Please note that an…
- risk 0.64cvss 9.8epss 0.05
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by sending specifically crafted objects to one…
- risk 0.64cvss 9.8epss 0.04
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
- risk 0.64cvss 9.8epss 0.03
A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login and ticket issuance. An attacker can use the 'class' property of the JSON request sent to the CLDB to influence the JSON library's…
- risk 0.64cvss 9.8epss 0.05
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
- risk 0.64cvss 9.8epss 0.05
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by…
- risk 0.64cvss 9.8epss 0.01
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID:…
- risk 0.64cvss 9.8epss 0.03
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions:…
- risk 0.64cvss 9.8epss 0.02
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
- risk 0.64cvss 9.8epss 0.02
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.