CWE-502
3,210 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (3,210)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the a...Show more |
3Fedoraproject OpenstackRedhat7Enterprise Linux Server FedoraGluster Storage Management Console+4 moreApr 29, 2026 Oct 22, 2012 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a cra...Show more |
view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary...Show more |
1Tiki 1Tikiwiki Cms/groupware Apr 29, 2026 Jul 12, 2012 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printst...Show more |
1Vmware 2Spring Framework Spring SecurityApr 29, 2026 Oct 4, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended...Show more |
2Fedoraproject Redhat2Fedora System Config FirewallApr 29, 2026 Jul 21, 2011 N/A· v4 7.8 HIGH· v3 6.0 MEDIUM· v2 fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted se...Show more |
The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to...Show more |
The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attack vectors. |
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables,...Show more |
2Mozilla Sco2Mozilla OpenserverApr 16, 2026 Oct 7, 2003 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialize...Show more |