VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 42 of 156
  • CVE-2019-15780CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

  • CVE-2018-20987CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.

  • CVE-2019-11030CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a…

  • CVE-2019-15321CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.

  • CVE-2019-15320CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.

  • CVE-2019-15319CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.

  • CVE-2018-20984CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.

  • CVE-2018-11779CriJul 26, 2019
    risk 0.64cvss 9.8epss 0.03

    In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.

  • CVE-2019-11011CriJun 21, 2019
    risk 0.64cvss 9.8epss 0.03

    Akamai CloudTest before 58.30 allows remote code execution.

  • CVE-2018-15890CriJun 20, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.

  • CVE-2019-12241CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.

  • CVE-2019-12240CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.

  • CVE-2019-11831CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.06

    The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.

  • CVE-2019-11830CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.

  • CVE-2019-0187CriMar 6, 2019
    risk 0.64cvss 9.8epss 0.03

    Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests…

  • CVE-2019-9212CriFeb 27, 2019
    risk 0.64cvss 9.8epss 0.03

    SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget. NOTE: The vendor…

  • CVE-2019-7743CriFeb 12, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.

  • CVE-2019-6503CriJan 22, 2019
    risk 0.64cvss 9.8epss 0.02

    There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method.

  • CVE-2018-20732CriJan 17, 2019
    risk 0.64cvss 9.8epss 0.04

    SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.

  • CVE-2018-20718CriJan 15, 2019
    risk 0.64cvss 9.8epss 0.04

    In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.