VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 75 of 167
  • CVE-2023-35184HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse a SolarWinds service resulting in a remote code execution.

  • CVE-2023-35182HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.02

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server.

  • CVE-2023-43668CriOct 16, 2023
    risk 0.57cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile".... .   Users are advised to upgrade…

  • CVE-2023-43176HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.02

    A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

  • CVE-2023-43268HigOct 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

  • CVE-2023-44273CriSep 28, 2023
    risk 0.57cvss 9.8epss 0.01

    Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.

  • CVE-2023-36757HigSep 12, 2023
    risk 0.57cvss 8.0epss 0.37

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-41330CriSep 6, 2023
    risk 0.57cvss 9.8epss 0.02

    knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2…

  • CVE-2023-40595HigAug 30, 2023
    risk 0.57cvss 8.8epss 0.01

    In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.

  • CVE-2023-39106HigAug 21, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.

  • CVE-2023-36480CriAug 4, 2023
    risk 0.57cvss 9.8epss 0.02

    The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it…

  • CVE-2023-38647CriJul 26, 2023
    risk 0.57cvss 9.8epss 0.02

    An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code…

  • CVE-2023-37895CriJul 25, 2023
    risk 0.57cvss 9.8epss 0.03

    Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that…

  • CVE-2023-28754HigJul 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file. The attacker needs to have permission to modify the ShardingSphere Agent YAML configuration file…

  • CVE-2023-33134HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.03

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2023-30262HigJun 9, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacker to execute arbitrary code via the RMI Registry service.

  • CVE-2023-33284HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.

  • CVE-2020-36718CriJun 7, 2023
    risk 0.57cvss 9.8epss 0.02

    The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object.

  • CVE-2023-2500HigMay 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers,…

  • CVE-2023-32336HigMay 22, 2023
    risk 0.57cvss 8.8epss 0.01

    IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.