CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (p...Show more |
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interacti...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Oct 13, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object. |
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized...Show more |
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to...Show more |
1Redhat 1Jboss Operations Network May 6, 2026 Sep 27, 2016 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related...Show more |
2Apache Redhat3Activemq Artemis ArtemisJboss Enterprise Application PlatformJun 15, 2026 Sep 27, 2016 N/A· v4 7.2 HIGH· v3 6.0 MEDIUM· v2 The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with...Show more |
ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via craf...Show more |
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections lib...Show more |
1Ibm 7Sterling B2b Integrator Sterling IntegratorTivoli Common Reporting+4 moreApr 21, 2026 Jan 2, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java o...Show more |
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformMay 6, 2026 Nov 25, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-c...Show more |
1Oracle 3Storagetek Tape Analytics Sw Tool Virtual Desktop InfrastructureWeblogic ServerApr 21, 2026 Nov 18, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP por...Show more |
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a dif...Show more |
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the a...Show more |
3Fedoraproject OpenstackRedhat7Enterprise Linux Server FedoraGluster Storage Management Console+4 moreApr 29, 2026 Oct 22, 2012 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a cra...Show more |
view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary...Show more |
1Tiki 1Tikiwiki Cms/groupware Apr 29, 2026 Jul 12, 2012 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printst...Show more |
1Vmware 2Spring Framework Spring SecurityApr 29, 2026 Oct 4, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended...Show more |
2Fedoraproject Redhat2Fedora System Config FirewallApr 29, 2026 Jul 21, 2011 N/A· v4 7.8 HIGH· v3 6.0 MEDIUM· v2 fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted se...Show more |