CWE-502
3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,196)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution. |
MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// U...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Dec 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID:...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformNov 5, 2025 Dec 10, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invo...Show more |
2Redhat Rubyonrails2Cloudforms RailsNov 21, 2024 Nov 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they shoul...Show more |
VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locatio...Show more |
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class. |
ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class. |
2Debian Phpbb2Debian Linux PhpbbNov 21, 2024 Nov 17, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with fo...Show more |
4Debian FedoraprojectPhpmailer Project+1 more4Debian Linux FedoraPhpmailer+1 moreNov 21, 2024 Nov 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. |
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to inse...Show more |
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service,...Show more |
4Canonical DebianOracle+1 more4Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxSystemd+1 moreJun 9, 2025 Oct 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to ro...Show more |
* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into J...Show more |
An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker ca...Show more |
1Microfocus 1Real User Monitoring Nov 21, 2024 Oct 23, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary...Show more |
1Avaya 1Avaya Aura System Platform Nov 21, 2024 Oct 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions...Show more |
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerab...Show more |