VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 94 of 156
  • CVE-2023-3513HigJul 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and triggering an insecure .NET…

  • CVE-2023-35317HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.02

    Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

  • CVE-2023-21124HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-2561HigMar 29, 2023
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2023-26547HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2023-1399HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.01

    N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.

  • CVE-2023-1145HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

  • CVE-2023-27978HigMar 21, 2023
    risk 0.51cvss 7.8epss 0.06

    A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS…

  • CVE-2023-20944HigFeb 28, 2023
    risk 0.51cvss 7.8epss 0.00

    In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21779HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Visual Studio Code Remote Code Execution Vulnerability

  • CVE-2022-32601HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07319132; Issue ID: ALPS07319132.

  • CVE-2022-42919HigNov 7, 2022
    risk 0.51cvss 7.8epss 0.01

    Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same…

  • CVE-2022-26472HigOct 7, 2022
    risk 0.51cvss 7.8epss 0.00

    In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07319095; Issue ID: ALPS07319095.

  • CVE-2022-26471HigOct 7, 2022
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07319121; Issue ID:…

  • CVE-2022-36006HigAug 15, 2022
    risk 0.51cvss 7.9epss 0.02

    Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted…

  • CVE-2022-35872HigJul 25, 2022
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…

  • CVE-2022-33320HigJul 20, 2022
    risk 0.51cvss 7.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics…

  • CVE-2022-33316HigJul 20, 2022
    risk 0.51cvss 7.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics…

  • CVE-2022-33315HigJul 20, 2022
    risk 0.51cvss 7.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics…

  • CVE-2022-27580HigJul 19, 2022
    risk 0.51cvss 7.8epss 0.00

    A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code…