Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Odoo MEDIUM 6.5
CVE-2017-10803

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database A…

Patch available
Fix from $1,600 2017-07-04
Mcollective CRITICAL 9.0
CVE-2017-2292

Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution …

Fix: after 2.10.3
Fix from $2,300 2017-06-30
Crashplan CRITICAL 9.8
CVE-2017-9830EPSS 6%

Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it cr…

Mitigation only
Fix from $2,300 2017-06-27
Breeze.server.net CRITICAL 9.8
CVE-2017-9424

IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deseria…

Fix: after 1.6.0
Fix from $2,300 2017-06-22
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-7050EPSS 5%

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…

Mitigation only
Fix from $2,300 2017-06-08
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2016-3690EPSS 5%

The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.

Mitigation only
Fix from $2,300 2017-06-08
Media Server CRITICAL 9.8
CVE-2017-5878

The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attack…

Mitigation only
Fix from $2,300 2017-06-08
Vsphere Data Protection CRITICAL 9.8
CVE-2017-4914EPSS 9%

VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote a…

Patch available
Fix from $2,300 2017-06-07
Iam CRITICAL 9.8
CVE-2017-9363

Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted auth…

Fix: after 1.7.4
Fix from $2,300 2017-06-02
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7504EPSS 29%

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se…

Fix: after 4.0
Fix from $2,300 2017-05-19
Lintian HIGH 7.8
CVE-2017-8829

Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with …

Fix: after 2.5.50.3
Fix from $1,950 2017-05-08
Glibc HIGH 7.5
CVE-2017-8804EPSS 8%

The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remo…

Patch available
Fix from $1,950 2017-05-07
Coldfusion CRITICAL 9.8
CVE-2017-3066 KEVEPSS 91%

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vuln…

Patch available
Fix from $2,300 2017-04-27
Dolby Audio X2 HIGH 7.8
CVE-2017-7293

The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privile…

No fix yet
Fix from $1,950 2017-04-26
Log4j CRITICAL 9.8
CVE-2017-5645EPSS 90%

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a …

Fix: 2.8.2+
Fix from $2,300 2017-04-17
Tomee CRITICAL 9.8
CVE-2016-0779EPSS 10%

The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted s…

Fix: after 1.7.3
Fix from $2,300 2017-04-11
Debian Linux HIGH 7.5
CVE-2016-4483EPSS 6%

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds rea…

Fix: 2.9.4+
Fix from $1,950 2017-04-11
Jira CRITICAL 9.8
CVE-2017-5983EPSS 16%

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers…

Mitigation only
Fix from $2,300 2017-04-10
Netweaver Application Server Java MEDIUM 6.5
CVE-2016-10304

The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and ser…

Mitigation only
Fix from $1,600 2017-04-10
Nutch CRITICAL 9.8
CVE-2016-6809EPSS 8%

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d…

Fix: after 1.13
Fix from $2,300 2017-04-06
Camel CRITICAL 9.8
CVE-2016-8749EPSS 11%

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

No fix yet
Fix from $2,300 2017-03-28
Phpmemcachedadmin CRITICAL 9.8
CVE-2014-8731EPSS 12%

PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of t…

Fix: after 1.2.2
Fix from $2,300 2017-03-23
Satellite CRITICAL 9.8
CVE-2017-5929EPSS 8%

QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

Fix: 1.2.0+
Fix from $2,300 2017-03-13
Camel CRITICAL 9.8
CVE-2017-3159EPSS 6%

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to secur…

Fix: after 2.18.1
Fix from $2,300 2017-03-07
Revive Adserver CRITICAL 9.8
CVE-2017-5830

Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.

Fix: after 4.0.0
Fix from $2,300 2017-03-03
Websphere Mq Jms CRITICAL 9.8
CVE-2016-0360

IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malici…

Mitigation only
Fix from $2,300 2017-02-15
Serialize To Js CRITICAL 9.8
CVE-2017-5954

An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to a…

Patch available
Fix from $2,300 2017-02-10
Node Serialize CRITICAL 9.8
CVE-2017-5941EPSS 61%

An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to ac…

Fix: after 0.0.4
Fix from $2,300 2017-02-09
Gradle CRITICAL 9.8
CVE-2016-6199

ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.

No fix yet
Fix from $2,300 2017-02-07
Zimbra Collaboration Suite CRITICAL 9.1
CVE-2016-3415

Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.

Fix: after 8.6.0
Fix from $2,300 2017-01-18