VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 67 of 156
  • CVE-2024-24551HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

  • CVE-2024-5724HigJun 19, 2024
    risk 0.57cvss 8.8epss 0.01

    The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.3 via deserialization of untrusted input 'PVGM_all_photos_details' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2024-35249HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.03

    Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability

  • CVE-2024-36528HigJun 10, 2024
    risk 0.57cvss 8.8epss 0.01

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.

  • CVE-2024-37060HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.

  • CVE-2024-37059HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37058HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37057HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37056HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37055HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37054HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37053HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37052HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-3954HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a new ditty. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object.…

  • CVE-2024-26579CriMay 8, 2024
    risk 0.57cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it. …

  • CVE-2024-3240HigMay 4, 2024
    risk 0.57cvss 8.8epss 0.01

    The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_info_bar' shortcode. This makes it possible for authenticated…

  • CVE-2023-50222HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is…

  • CVE-2023-50221HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User…

  • CVE-2023-50220HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to…

  • CVE-2023-50219HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit…