VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 75 of 156
  • CVE-2019-11666HigSep 17, 2019
    risk 0.57cvss 8.8epss 0.01

    Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data.

  • CVE-2019-16335CriSep 15, 2019
    risk 0.57cvss 9.8epss 0.05

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

  • CVE-2019-5069HigSep 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.

  • CVE-2018-11307CriJul 9, 2019
    risk 0.57cvss 9.8epss 0.06

    An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

  • CVE-2019-10069CriMay 31, 2019
    risk 0.57cvss 9.8epss 0.03

    In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.

  • CVE-2019-6980CriMay 29, 2019
    risk 0.57cvss 9.8epss 0.04

    Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.

  • CVE-2017-18375HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.02

    Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.

  • CVE-2016-10753HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.02

    e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

  • CVE-2019-9056HigApr 11, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object…

  • CVE-2019-9061HigMar 26, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.

  • CVE-2019-9057HigMar 26, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.

  • CVE-2019-1000005HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.02

    mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted…

  • CVE-2018-6162HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-14720CriJan 2, 2019
    risk 0.57cvss 9.8epss 0.08

    FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

  • CVE-2018-14719CriJan 2, 2019
    risk 0.57cvss 9.8epss 0.10

    FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

  • CVE-2018-18987HigNov 30, 2018
    risk 0.57cvss 8.8epss 0.03

    VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote…

  • CVE-2018-19296HigNov 16, 2018
    risk 0.57cvss 8.8epss 0.02

    PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

  • CVE-2018-18628CriOct 23, 2018
    risk 0.57cvss 9.8epss 0.05

    An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, base64 encode it, and place it…

  • CVE-2018-18240CriOct 11, 2018
    risk 0.57cvss 9.8epss 0.04

    Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.

  • CVE-2016-9045HigSep 17, 2018
    risk 0.57cvss 8.8epss 0.02

    A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.