← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pippo
1Pippo
Nov 21, 2024
Oct 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.
1Cisco
1Identity Services Engine
Nov 21, 2024
Oct 5, 2018
N/A· v4
4.7 MEDIUM· v3
6.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.Show less
1Zohocorp
1Manageengine Applications Manager
Nov 21, 2024
Sep 26, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.
1Getmonero
1Monero
Nov 21, 2024
Sep 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and other cryptocurrencies. A specially craf...Show more
An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and other cryptocurrencies. A specially crafted network packet can cause a logic flaw, resulting in code execution. An attacker can send a packet to trigger this vulnerability.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code ex...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code ex...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code ex...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code ex...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Processmaker
1Processmaker
Nov 21, 2024
Sep 17, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can...Show more
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.Show less
2Limesurvey
Tecnick
2Limesurvey
Tcpdf
Nov 21, 2024
Sep 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
1Infinispan
1Infinispan
Nov 21, 2024
Sep 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object...Show more
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.Show less
1Ibm
1Websphere Application Server
Nov 21, 2024
Sep 7, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.
4Debian
GlusterOpensuse+1 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Nov 21, 2024
Sep 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
1Docker
1Docker
Nov 21, 2024
Sep 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the dese...Show more
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not otherwise have administrator access) to escalate to administrator privileges.Show less
1Trendmicro
4Antivirus + Security
Internet SecurityMaximum Security+1 more
Nov 21, 2024
Aug 30, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must fi...Show more
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.Show less
1Broadcom
1Release Automation
Nov 21, 2024
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.
1Pyconuk
1Conference Scheduler Cli
Nov 21, 2024
Aug 28, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.
1Hazzardweb
1Easylogin Pro
Nov 21, 2024
Aug 24, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.
1Jenkins
1Jenkins
Nov 21, 2024
Aug 23, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
1Yeswiki
1Yeswiki
Nov 21, 2024
Aug 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that can result in execution of code, disclosure of information.