VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 72 of 156
  • CVE-2022-28684HigAug 3, 2022
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit this vulnerability. The specific flaw exists within the SafeBinaryFormatter library. The issue results from the lack of proper…

  • CVE-2022-2437CriJul 18, 2022
    risk 0.57cvss 9.8epss 0.02

    The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a…

  • CVE-2022-30981HigJul 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence can potentially achieve Java code execution.

  • CVE-2022-31605CriJul 1, 2022
    risk 0.57cvss 9.8epss 0.02

    NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of…

  • CVE-2022-31604CriJul 1, 2022
    risk 0.57cvss 9.8epss 0.02

    NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged network attacker to cause Remote Code…

  • CVE-2022-32511CriJun 6, 2022
    risk 0.57cvss 9.8epss 0.02

    jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

  • CVE-2021-32935HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.02

    The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.

  • CVE-2022-1118HigMay 17, 2022
    risk 0.57cvss 8.6epss 0.11

    Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This allows attackers to craft a malicious…

  • CVE-2022-0573HigMay 16, 2022
    risk 0.57cvss 8.8epss 0.02

    JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient…

  • CVE-2022-1463HigMay 10, 2022
    risk 0.57cvss 8.8epss 0.02

    The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.

  • CVE-2022-29936HigApr 29, 2022
    risk 0.57cvss 8.8epss 0.02

    USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation product.

  • CVE-2022-24289HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.02

    Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) feature is a web services-based technology that provides object persistence and query functionality to 'remote' applications. In Apache…

  • CVE-2021-43360HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.02

    Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authenticated remote attacker with database access privilege, to execute arbitrary code and control the system or interrupt services.

  • CVE-2021-39321HigOct 21, 2021
    risk 0.57cvss 8.8epss 0.02

    Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the…

  • CVE-2021-36231HigAug 31, 2021
    risk 0.57cvss 8.8epss 0.03

    Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.

  • CVE-2021-39141HigAug 23, 2021
    risk 0.57cvss 8.5epss 0.16

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed…

  • CVE-2021-36483HigAug 4, 2021
    risk 0.57cvss 8.8epss 0.03

    DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

  • CVE-2021-37578CriJul 29, 2021
    risk 0.57cvss 9.8epss 0.04

    Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocations. A remote…

  • CVE-2021-24280HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.02

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.

  • CVE-2020-36326CriApr 28, 2021
    risk 0.57cvss 9.8epss 0.03

    PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by…