Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
phpMyAdmin CRITICAL 9.8
CVE-2016-9865

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnseria…

Patch available
Fix from $2,300 2016-12-11
phpMyAdmin CRITICAL 9.8
CVE-2016-6620

An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. Th…

Patch available
Fix from $2,300 2016-12-11
Jboss Enterprise Application Platform HIGH 8.8
CVE-2016-7065EPSS 12%

The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos…

No fix yet
Fix from $1,950 2016-10-13
Myfaces Trinidad CRITICAL 9.8
CVE-2016-5019EPSS 8%

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow…

Fix: 1.0.13 / 1.2.15+
Fix from $2,300 2016-10-03
Network Automation HIGH 7.3
CVE-2016-4385

The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execu…

Mitigation only
Fix from $1,950 2016-09-29
Jboss Operations Network CRITICAL 9.8
CVE-2016-6330EPSS 11%

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…

Mitigation only
Fix from $2,300 2016-09-27
Artemis HIGH 7.2
CVE-2016-4978EPSS 7%

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache Ac…

Fix: 1.4.0+
Fix from $1,950 2016-09-27
PHP CRITICAL 9.8
CVE-2016-7124EPSS 17%

ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause…

Fix: after 5.6.24
Fix from $2,300 2016-09-12
Coldfusion CRITICAL 9.8
CVE-2016-1114EPSS 9%

Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafte…

Mitigation only
Fix from $2,300 2016-05-11
Sterling B2b Integrator CRITICAL 9.8
CVE-2015-7450 KEVEPSS 98%

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote …

Fix: after 10.0.0.2
Fix from $2,300 2016-01-02
Commons Collections CRITICAL 9.8
CVE-2015-6420EPSS 18%

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and…

Fix: 3.2.2+
Fix from $2,300 2015-12-15
Openshift Container Platform CRITICAL 9.8
CVE-2015-8103EPSS 87%

The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J…

Fix: 1.625.2 / 1.638+
Fix from $2,300 2015-11-25
Virtual Desktop Infrastructure CRITICAL 9.8
CVE-2015-4852 KEVEPSS 96%

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands…

Fix: after 3.5.2
Fix from $2,300 2015-11-18
Restlet HIGH 7.5
CVE-2013-4271

The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote …

Fix: after 2.1.3
Fix from $1,950 2013-10-10
Cubecart CRITICAL 9.8
CVE-2013-1465EPSS 7%

The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objec…

Fix: after 5.2.0
Fix from $2,300 2013-02-08
Fedora CRITICAL 9.8
CVE-2012-4406EPSS 7%

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memca…

Fix: 1.7.0+
Fix from $2,300 2012-10-22
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2012-0911EPSS 63%

TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1)…

Fix: 6.7 / 8.4+
Fix from $2,300 2012-07-12
Spring Framework MEDIUM 6.8
CVE-2011-2894EPSS 9%

Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects fr…

Fix: after 3.0.5
Fix from $1,600 2011-10-04
System Config Firewall HIGH 7.8
CVE-2011-2520

fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the bac…

Fix: after 1.2.29
Fix from $1,950 2011-07-21
Chrome HIGH 7.5
CVE-2010-4574

The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not…

Fix: 8.0.552.224 / 8.0.552.343+
Fix from $1,950 2010-12-22
Chrome HIGH 9.3
CVE-2010-3258

The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attac…

Fix: 6.0.472.53+
Fix from $1,950 2010-09-07
Mozilla CRITICAL 9.8
CVE-2003-0791

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as …

Fix: after 1.4
Fix from $2,300 2003-10-07