VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 70 of 156
  • CVE-2023-28754HigJul 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file. The attacker needs to have permission to modify the ShardingSphere Agent YAML configuration file…

  • CVE-2023-33134HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.03

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2023-30262HigJun 9, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacker to execute arbitrary code via the RMI Registry service.

  • CVE-2023-33284HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.

  • CVE-2020-36718CriJun 7, 2023
    risk 0.57cvss 9.8epss 0.02

    The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object.

  • CVE-2023-2500HigMay 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers,…

  • CVE-2023-32336HigMay 22, 2023
    risk 0.57cvss 8.8epss 0.01

    IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.

  • CVE-2023-1196HigMay 2, 2023
    risk 0.57cvss 8.8epss 0.01

    The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.

  • CVE-2023-1381HigApr 10, 2023
    risk 0.57cvss 8.8epss 0.02

    The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to…

  • CVE-2023-29215CriApr 10, 2023
    risk 0.57cvss 9.8epss 0.02

    In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. Therefore, the parameters…

  • CVE-2023-20102HigApr 5, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient sanitization of user-provided data that…

  • CVE-2023-1139HigMar 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

  • CVE-2023-28115CriMar 17, 2023
    risk 0.57cvss 9.8epss 0.03

    Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker…

  • CVE-2023-21713HigFeb 14, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft SQL Server Remote Code Execution Vulnerability

  • CVE-2023-24997CriFeb 1, 2023
    risk 0.57cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223…

  • CVE-2022-44645HigJan 31, 2023
    risk 0.57cvss 8.8epss 0.02

    In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and malicious parameters.…

  • CVE-2022-45923HigJan 18, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker to increase/decrease an arbitrary memory address by 1 and trigger a call to a method of a vftable with a vftable pointer value…

  • CVE-2023-22850HigJan 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.

  • CVE-2023-21744HigJan 10, 2023
    risk 0.57cvss 8.8epss 0.03

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2021-33420CriDec 15, 2022
    risk 0.57cvss 9.8epss 0.02

    A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.