VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 82 of 167
  • CVE-2017-18342CriJun 27, 2018
    risk 0.57cvss 9.8epss 0.06

    In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.

  • CVE-2018-6497HigJun 16, 2018
    risk 0.57cvss 8.8epss 0.01

    Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe…

  • CVE-2018-6496HigJun 16, 2018
    risk 0.57cvss 8.8epss 0.01

    Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).

  • CVE-2018-1131HigMay 15, 2018
    risk 0.57cvss 8.8epss 0.01

    Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code…

  • CVE-2014-3539CriApr 6, 2018
    risk 0.57cvss 9.8epss 0.03

    base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.

  • CVE-2017-8967HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8966HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.03

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8965HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8964HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8963HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8962HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.03

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2018-1000058HigFeb 9, 2018
    risk 0.57cvss 8.8epss 0.03

    Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore…

  • CVE-2018-1000048HigFeb 9, 2018
    risk 0.57cvss 8.8epss 0.02

    NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution. This attack appear to be exploitable via Victim tries to retrieve and process a weather data file.

  • CVE-2018-1000047HigFeb 9, 2018
    risk 0.57cvss 8.8epss 0.02

    NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This attack appear to be exploitable via Victim opens an untrusted file for optimization using Kodiak library.

  • CVE-2016-3957CriFeb 6, 2018
    risk 0.57cvss 9.8epss 0.05

    The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowledge of encryption_key.

  • CVE-2017-15095CriFeb 6, 2018
    risk 0.57cvss 9.8epss 0.08

    A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the…

  • CVE-2014-9515CriDec 29, 2017
    risk 0.57cvss 9.8epss 0.06

    Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

  • CVE-2017-1000207HigNov 27, 2017
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and…

  • CVE-2017-1000248CriNov 17, 2017
    risk 0.57cvss 9.8epss 0.02

    Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis

  • CVE-2017-1000208HigNov 17, 2017
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<=…