VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 93 of 156
  • CVE-2024-45857HigSep 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.

  • CVE-2024-6675HigJul 22, 2024
    risk 0.51cvss 7.8epss 0.00

    A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects VeriStand 2024 Q2 and prior…

  • CVE-2024-31317HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe deserialization. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not…

  • CVE-2024-38023HigJul 9, 2024
    risk 0.51cvss 7.2epss 0.53

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-45147HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when…

  • CVE-2024-3467HigJun 12, 2024
    risk 0.51cvss 7.8epss 0.00

    There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.

  • CVE-2024-28964HigJun 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user.…

  • CVE-2024-37065HigJun 4, 2024
    risk 0.51cvss 7.8epss 0.00

    Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.

  • CVE-2024-37064HigJun 4, 2024
    risk 0.51cvss 7.8epss 0.00

    Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded.

  • CVE-2024-37062HigJun 4, 2024
    risk 0.51cvss 7.8epss 0.00

    Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded.

  • CVE-2024-3483HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.01

    Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

  • CVE-2024-30042HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.02

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2024-2229HigMar 18, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution when a malicious project file is loaded into the application by a valid user.

  • CVE-2023-7032HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.00

    A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.

  • CVE-2023-34052HigOct 20, 2023
    risk 0.51cvss 7.8epss 0.00

    VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.

  • CVE-2023-35669HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-28072HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A local malicious user could potentially send specially crafted requests to the .NET Remoting server to run arbitrary code on the system.

  • CVE-2023-24621HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.

  • CVE-2021-31681HigJul 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.

  • CVE-2021-31680HigJul 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file.