Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Redis Store CRITICAL 9.8
CVE-2017-1000248

Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis

Fix: after 1.3.0
Fix from $2,300 2017-11-17
Swagger Codegen HIGH 8.8
CVE-2017-1000208

A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafte…

Fix: after 2.2.2
Fix from $1,950 2017-11-17
October HIGH 7.5
CVE-2017-1000195

October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissi…

Fix: after 1.0.412
Fix from $1,950 2017-11-17
Camel CRITICAL 9.8
CVE-2017-12633EPSS 7%

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. D…

Fix: 2.19.4 / 2.20.1+
Fix from $2,300 2017-11-15
Camel CRITICAL 9.8
CVE-2017-12634EPSS 7%

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De…

Fix: 2.19.4+
Fix from $2,300 2017-11-15
Data Grid CRITICAL 9.8
CVE-2015-7501EPSS 86%

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pl…

Mitigation only
Fix from $2,300 2017-11-09
Mahara HIGH 8.8
CVE-2017-1000148

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of t…

Patch available
Fix from $1,950 2017-11-03
Ws Xmlrpc CRITICAL 9.8
CVE-2016-5003EPSS 15%

The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…

No fix yet
Fix from $2,300 2017-10-27
Openmrs CRITICAL 9.8
CVE-2017-12796

The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate user…

Fix: 2.6.1+
Fix from $2,300 2017-10-23
James Server HIGH 7.8
CVE-2017-12628

The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to ex…

Fix: after 3.0.0
Fix from $1,950 2017-10-20
Qpid HIGH 7.2
CVE-2015-5164

The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access o…

Mitigation only
Fix from $1,950 2017-10-18
Openmeetings CRITICAL 9.8
CVE-2016-8736

Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.

Fix: 3.1.2+
Fix from $2,300 2017-10-12
Debian Linux CRITICAL 9.8
CVE-2017-0903EPSS 16%

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specificatio…

Patch available
Fix from $2,300 2017-10-11
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…

Mitigation only
Fix from $2,300 2017-10-04
Android HIGH 7.8
CVE-2017-0806

An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0…

Patch available
Fix from $1,950 2017-10-04
Ers Data System CRITICAL 9.8
CVE-2017-14702EPSS 8%

ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserializ…

No fix yet
Fix from $2,300 2017-09-30
Nr8120 Firmware CRITICAL 9.8
CVE-2017-10932

All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the a…

Fix: 12.17.20+
Fix from $2,300 2017-09-28
Kaltura Server HIGH 7.2
CVE-2017-14141

The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection …

Fix: 13.2.0+
Fix from $1,950 2017-09-19
Struts HIGH 8.1
CVE-2017-9805 KEVEPSS 99%

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for des…

Fix: 2.3.34 / 2.5.13+
Fix from $1,950 2017-09-15
Brooklyn HIGH 8.8
CVE-2016-8744

Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal…

Fix: after 0.9.0
Fix from $1,950 2017-09-13
Spark HIGH 7.8
CVE-2017-12612

In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched …

Mitigation only
Fix from $1,950 2017-09-13
Crushftp CRITICAL 9.8
CVE-2017-14035

CrushFTP 8.x before 8.2.0 has a serialization vulnerability.

No fix yet
Fix from $2,300 2017-08-30
Photo Station CRITICAL 9.8
CVE-2017-11153EPSS 12%

Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain a…

Fix: after 6.7.2-3429
Fix from $2,300 2017-08-08
Nancy CRITICAL 9.8
CVE-2017-9785

Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.

Fix: after 1.4.3
Fix from $2,300 2017-07-20
Akka HIGH 8.1
CVE-2017-1000034EPSS 6%

Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the…

Fix: after 2.4.16
Fix from $1,950 2017-07-17
Plug HIGH 8.1
CVE-2017-1000053

Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.

Fix: 1.0.4 / 1.1.7+
Fix from $1,950 2017-07-17
Wicket CRITICAL 9.1
CVE-2016-6793EPSS 8%

The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop…

Fix: 1.5.17 / 6.25.0+
Fix from $2,300 2017-07-17
Netweaver HIGH 7.5
CVE-2017-9844EPSS 6%

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java…

Mitigation only
Fix from $1,950 2017-07-12
Debian Linux CRITICAL 9.8
CVE-2016-4000EPSS 6%

Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.

Patch available
Fix from $2,300 2017-07-06
Debian Linux HIGH 8.2
CVE-2017-2295

Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. …

Fix: after 4.10.0
Fix from $1,950 2017-07-05