← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Ignite
Nov 21, 2024
Apr 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are...Show more
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.Show less
1Myscript
1Myscript
Nov 21, 2024
Mar 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The MyScript SDK before 1.3 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
1Ibm
1Db2
Nov 21, 2024
Mar 22, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execu...Show more
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.Show less
1Osisoft
1Pi Data Archive
Jun 17, 2026
Mar 14, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deserialized data to send custom requests that crash the server.
1Rubygems
1Rubygems
Nov 21, 2024
Mar 13, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of...Show more
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack appear to be exploitable via victim must run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability appears to have been fixed in 2.7.6.Show less
1Redhat
1Jboss Enterprise Application Platform
Nov 21, 2024
Mar 9, 2018
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of s...Show more
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of service attack.Show less
1Calibre Ebook
1Calibre
Jun 17, 2026
Mar 8, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contain...Show more
gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.Show less
1Cisco
1Secure Access Control System
Jan 14, 2026
Mar 8, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. T...Show more
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.Show less
1Apache
1Geode
Nov 21, 2024
Feb 27, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the c...Show more
In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code execution if certain classes are present on the classpath.Show less
1Apache
1Geode
Nov 21, 2024
Feb 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code executio...Show more
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the classpath.Show less
4Debian
FasterxmlOracle+1 more
5Communications Billing And Revenue Management
Communications Instant Messaging ServerDebian Linux+2 more
Jun 17, 2026
Feb 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploi...Show more
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.Show less
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.