CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,116)
page 42 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15780 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2019 | The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. | ||
| CVE-2018-20987 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. | ||
| CVE-2019-11030 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a… | ||
| CVE-2019-15321 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. | ||
| CVE-2019-15320 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. | ||
| CVE-2019-15319 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. | ||
| CVE-2018-20984 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. | ||
| CVE-2018-11779 | Cri | 0.64 | 9.8 | 0.03 | Jul 26, 2019 | In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class. | ||
| CVE-2019-11011 | Cri | 0.64 | 9.8 | 0.03 | Jun 21, 2019 | Akamai CloudTest before 58.30 allows remote code execution. | ||
| CVE-2018-15890 | Cri | 0.64 | 9.8 | 0.03 | Jun 20, 2019 | An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server. | ||
| CVE-2019-12241 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2019 | The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php. | ||
| CVE-2019-12240 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2019 | The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. | ||
| CVE-2019-11831 | Cri | 0.64 | 9.8 | 0.06 | May 9, 2019 | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL. | ||
| CVE-2019-11830 | Cri | 0.64 | 9.8 | 0.03 | May 9, 2019 | PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism. | ||
| CVE-2019-0187 | Cri | 0.64 | 9.8 | 0.03 | Mar 6, 2019 | Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests… | ||
| CVE-2019-9212 | Cri | 0.64 | 9.8 | 0.03 | Feb 27, 2019 | SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget. NOTE: The vendor… | ||
| CVE-2019-7743 | Cri | 0.64 | 9.8 | 0.03 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files. | ||
| CVE-2019-6503 | Cri | 0.64 | 9.8 | 0.02 | Jan 22, 2019 | There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method. | ||
| CVE-2018-20732 | Cri | 0.64 | 9.8 | 0.04 | Jan 17, 2019 | SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant. | ||
| CVE-2018-20718 | Cri | 0.64 | 9.8 | 0.04 | Jan 15, 2019 | In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link. |
- risk 0.64cvss 9.8epss 0.02
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
- risk 0.64cvss 9.8epss 0.02
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
- risk 0.64cvss 9.8epss 0.02
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a…
- risk 0.64cvss 9.8epss 0.02
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
- risk 0.64cvss 9.8epss 0.02
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
- risk 0.64cvss 9.8epss 0.02
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
- risk 0.64cvss 9.8epss 0.02
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
- risk 0.64cvss 9.8epss 0.03
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
- risk 0.64cvss 9.8epss 0.03
Akamai CloudTest before 58.30 allows remote code execution.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.
- risk 0.64cvss 9.8epss 0.02
The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.
- risk 0.64cvss 9.8epss 0.02
The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.
- risk 0.64cvss 9.8epss 0.06
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
- risk 0.64cvss 9.8epss 0.03
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
- risk 0.64cvss 9.8epss 0.03
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests…
- risk 0.64cvss 9.8epss 0.03
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget. NOTE: The vendor…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
- risk 0.64cvss 9.8epss 0.02
There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method.
- risk 0.64cvss 9.8epss 0.04
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
- risk 0.64cvss 9.8epss 0.04
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.