VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 54 of 167
  • CVE-2023-40057CriFeb 15, 2024
    risk 0.59cvss 9.0epss 0.05

    The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.

  • CVE-2023-52202CriJan 8, 2024
    risk 0.59cvss 9.1epss 0.01

    Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.

  • CVE-2023-52205CriJan 8, 2024
    risk 0.59cvss 9.1epss 0.01

    Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.

  • CVE-2023-52207CriJan 8, 2024
    risk 0.59cvss 9.1epss 0.01

    Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.

  • CVE-2023-49777CriDec 31, 2023
    risk 0.59cvss 9.1epss 0.01

    Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.

  • CVE-2023-36035HigNov 14, 2023
    risk 0.59cvss 8.0epss 0.87

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-45146CriOct 18, 2023
    risk 0.59cvss 9.0epss 0.01

    XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized…

  • CVE-2023-36744HigSep 12, 2023
    risk 0.59cvss 8.0epss 0.57

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-2288HigMay 30, 2023
    risk 0.59cvss 8.8epss 0.18

    The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.

  • CVE-2022-47083HigJan 10, 2023
    risk 0.59cvss 8.8epss 0.18

    A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.

  • CVE-2022-36964HigNov 29, 2022
    risk 0.59cvss 8.8epss 0.17

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-39008CriSep 16, 2022
    risk 0.59cvss 9.1epss 0.01

    The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.

  • CVE-2022-24846CriApr 14, 2022
    risk 0.59cvss 9.1epss 0.01

    GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution. While in GeoWebCache the JNDI strings are…

  • CVE-2022-22005HigFeb 9, 2022
    risk 0.59cvss 8.8epss 0.17

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2021-41110CriOct 1, 2021
    risk 0.59cvss 9.1epss 0.03

    cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no…

  • CVE-2021-40102CriSep 24, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).

  • CVE-2021-23895CriJun 2, 2021
    risk 0.59cvss 9.0epss 0.02

    Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the…

  • CVE-2021-29508CriMay 11, 2021
    risk 0.59cvss 9.1epss 0.02

    Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the…

  • CVE-2019-11286CriJul 31, 2020
    risk 0.59cvss 9.1epss 0.02

    VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may…

  • CVE-2020-1439HigJul 14, 2020
    risk 0.59cvss 8.8epss 0.20

    A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.