← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
GlusterOpensuse+1 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Nov 21, 2024
Sep 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
1Docker
1Docker
Nov 21, 2024
Sep 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the dese...Show more
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not otherwise have administrator access) to escalate to administrator privileges.Show less
1Trendmicro
4Antivirus + Security
Internet SecurityMaximum Security+1 more
Nov 21, 2024
Aug 30, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must fi...Show more
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.Show less
1Broadcom
1Release Automation
Nov 21, 2024
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.
1Pyconuk
1Conference Scheduler Cli
Nov 21, 2024
Aug 28, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.
1Hazzardweb
1Easylogin Pro
Nov 21, 2024
Aug 24, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.
1Jenkins
1Jenkins
Nov 21, 2024
Aug 23, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
1Yeswiki
1Yeswiki
Nov 21, 2024
Aug 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that can result in execution of code, disclosure of information.
1Swoole
1Swoole
Nov 21, 2024
Aug 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.
1Cryo Project
1Cryo
Nov 21, 2024
Aug 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Jun 17, 2026
Aug 15, 2018
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7...Show more
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.Show less
2Eclipse
Oracle
2Enterprise Manager Base Platform
Openj9
Nov 21, 2024
Aug 14, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the abilit...Show more
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows, Linux and AIX JVMs and can be disabled using the command line option -Dcom.ibm.tools.attach.enable=no.Show less
1Jetbrains
2Dotpeek
Resharper Ultimate
Nov 21, 2024
Aug 13, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of...Show more
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.Show less
1Laravel
1Laravel
Nov 7, 2025
Aug 9, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illumi...Show more
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.Show less
1Hp
1Business Service Management
Nov 21, 2024
Aug 6, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collection Java Deserialization versions v9.20-v9.26
1Hp
1Network Node Manager I
Nov 21, 2024
Aug 6, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10 using Java Deserialization.
1Redhat
2Jboss A Mq
Jboss Fuse
Nov 21, 2024
Aug 1, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
1Redhat
2Jboss A Mq
Jboss Fuse
Nov 21, 2024
Aug 1, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the se...Show more
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.Show less
1Zte
1Zxiptv Epg Firmware
Nov 21, 2024
Jul 25, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An...Show more
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.Show less
1Apache
1Ignite
Jun 17, 2026
Jul 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party v...Show more
In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to GridClientJdkMarshaller deserialization endpoint.Show less