← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FasterxmlOracle+1 more
12Automation Manager
Business Process Management SuiteDebian Linux+9 more
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
4Debian
FasterxmlOracle+1 more
12Banking Platform
Communications Billing And Revenue ManagementDebian Linux+9 more
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
5Debian
FasterxmlNetapp+2 more
20Banking Platform
Business Process Management SuiteClusterware+17 more
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
5Debian
FasterxmlNetapp+2 more
25Banking Platform
Business Process Management SuiteCommunications Billing And Revenue Management+22 more
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
1Facebook
1Buck
Jun 17, 2026
Dec 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06...Show more
Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01.Show less
3Canonical
DebianPhp
3Debian Linux
Pear Archive TarUbuntu Linux
Nov 21, 2024
Dec 28, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is...Show more
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization by crafting a tar file with `phar://[path_to_malicious_phar_file]` as path. Object injection can be used to trigger destruct in the loaded PHP classes, e.g. the Archive_Tar class itself. With Archive_Tar object injection, arbitrary file deletion can occur because `@unlink($this->_temp_tarname)` is called. If another class with useful gadget is loaded, it may possible to cause remote code execution that can result in files being deleted or possibly modified. This vulnerability appears to have been fixed in 1.4.4.Show less
1Zoneminder
1Zoneminder
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
1Zoneminder
1Zoneminder
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
1Ubilling
1Ubilling
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
1Megamek
1Megamek
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Dec 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// U...Show more
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.Show less
1Ibm
1Websphere Application Server
Nov 21, 2024
Dec 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID:...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.Show less
2Jenkins
Redhat
2Jenkins
Openshift Container Platform
Nov 5, 2025
Dec 10, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invo...Show more
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.Show less
2Redhat
Rubyonrails
2Cloudforms
Rails
Nov 21, 2024
Nov 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they shoul...Show more
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.Show less
1Invt
1Vt Designer
Nov 21, 2024
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locatio...Show more
VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.Show less
1Vanillaforums
1Vanilla
Nov 21, 2024
Nov 23, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.
1Php
1Php
Nov 21, 2024
Nov 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.
2Debian
Phpbb
2Debian Linux
Phpbb
Nov 21, 2024
Nov 17, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with fo...Show more
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.Show less
4Debian
FedoraprojectPhpmailer Project+1 more
4Debian Linux
FedoraPhpmailer+1 more
Nov 21, 2024
Nov 16, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
1Cisco
1Unity Express
Nov 21, 2024
Nov 8, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to inse...Show more
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges.Show less