← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
1Hp
1Operations Orchestration
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found.
1Hp
1Network Automation
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was found.
1Infinispan
1Infinispan
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and at...Show more
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.Show less
1Validformbuilder
1Validform Builder
Nov 21, 2024
Feb 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in fil...Show more
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.Show less
1Jenkins
1Pipeline Supporting Apis
Nov 21, 2024
Feb 9, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts we...Show more
Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.Show less
1Nasa
1Rtretrievalframework
Nov 21, 2024
Feb 9, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution. This attack appear to be exploitable via Victim t...Show more
NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution. This attack appear to be exploitable via Victim tries to retrieve and process a weather data file.Show less
1Nasa
1Kodiak
Nov 21, 2024
Feb 9, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This attack appear to be exploitable via Victim opens an untrusted file for...Show more
NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This attack appear to be exploitable via Victim opens an untrusted file for optimization using Kodiak library.Show less
1Nasa
1Pyblock
Nov 21, 2024
Feb 9, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar...Show more
NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability appears to have been fixed in v1.4.Show less
1Nasa
1Singledop
Nov 21, 2024
Feb 9, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted...Show more
NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability appears to have been fixed in v1.1.Show less
1Web2py
1Web2py
Nov 21, 2024
Feb 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowle...Show more
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowledge of encryption_key.Show less