VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 72 of 167
  • CVE-2024-46983CriSep 19, 2024
    risk 0.57cvss 9.8epss 0.01

    sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the…

  • CVE-2024-45852HigSep 12, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.

  • CVE-2024-7435HigAug 31, 2024
    risk 0.57cvss 8.8epss 0.01

    The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known…

  • CVE-2024-2694HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.01

    The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access…

  • CVE-2024-7561HigAug 8, 2024
    risk 0.57cvss 8.8epss 0.01

    The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the wpeden_post_meta post meta value. This makes it possible for authenticated attackers, with Contributor-level access…

  • CVE-2024-7486HigAug 8, 2024
    risk 0.57cvss 8.8epss 0.01

    The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 via deserialization of untrusted input through the 'wpeden_post_meta' post meta. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2024-36131HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.02

    An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.

  • CVE-2024-6152HigJul 27, 2024
    risk 0.57cvss 8.8epss 0.01

    The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5 via deserialization of untrusted input in the flipbox_builder_Flipbox_ShortCode function. This makes it possible for authenticated attackers, with…

  • CVE-2024-40624CriJul 15, 2024
    risk 0.57cvss 9.8epss 0.01

    TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled cookies. One can use phpggc and the chain…

  • CVE-2023-49566HigJul 15, 2024
    risk 0.57cvss 8.8epss 0.01

    In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSource Manager Module will result in jndi injection. Therefore, the parameters in the DB2 URL should be blacklisted.  This attack…

  • CVE-2024-36984HigJul 1, 2024
    risk 0.57cvss 8.8epss 0.01

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

  • CVE-2024-39705CriJun 27, 2024
    risk 0.57cvss 9.8epss 0.01

    NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

  • CVE-2024-24551HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

  • CVE-2024-5724HigJun 19, 2024
    risk 0.57cvss 8.8epss 0.01

    The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.3 via deserialization of untrusted input 'PVGM_all_photos_details' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2024-35249HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.03

    Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability

  • CVE-2024-36528HigJun 10, 2024
    risk 0.57cvss 8.8epss 0.01

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.

  • CVE-2024-37060HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.

  • CVE-2024-37059HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37058HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37057HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.