Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Squirrelmail CRITICAL 9.8
CVE-2020-14932

compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.…

Mitigation only
Fix from $2,300 2020-06-20
Squirrelmail HIGH 8.8
CVE-2020-14933

compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor dispute…

Mitigation only
Fix from $1,950 2020-06-20
Rails CRITICAL 9.8
CVE-2020-8165EPSS 46%

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided…

Fix: 5.2.4.3 / 6.0.3.1+
Fix from $2,300 2020-06-19
Rails HIGH 7.5
CVE-2020-8164

A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be…

Fix: 5.2.4.3 / 6.0.3.1+
Fix from $1,950 2020-06-19
Active Iq Unified Manager HIGH 8.1
CVE-2020-14195

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jn…

Fix: 2.9.10.5+
Fix from $1,950 2020-06-16
Active Iq Unified Manager HIGH 8.1
CVE-2020-14060EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.…

Fix: 2.9.10.5+
Fix from $1,950 2020-06-14
Active Iq Unified Manager HIGH 8.1
CVE-2020-14061

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueC…

Fix: 2.9.10.5+
Fix from $1,950 2020-06-14
Active Iq Unified Manager HIGH 8.1
CVE-2020-14062EPSS 8%

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xal…

Fix: 2.9.10.5+
Fix from $1,950 2020-06-14
Spring Batch HIGH 8.1
CVE-2020-5411

When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixe…

Fix: after 4.2.2
Fix from $1,950 2020-06-11
Android MEDIUM 5.5
CVE-2020-0132

In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local …

Patch available
Fix from $1,600 2020-06-11
Phpmussel CRITICAL 9.8
CVE-2020-4043

phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to a…

Fix: 1.6.0+
Fix from $2,300 2020-06-10
Ignition Gateway HIGH 7.5
CVE-2020-10644EPSS 20%

The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (…

Fix: 7.9.14 / 8.0.10+
Fix from $1,950 2020-06-09
Ignition Gateway HIGH 7.5
CVE-2020-12000

The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, wh…

Fix: 7.9.14 / 8.0.10+
Fix from $1,950 2020-06-09
Websphere Application Server CRITICAL 9.8
CVE-2020-4448EPSS 12%

IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with…

Fix: 8.5.5.18 / 9.0.5.4+
Fix from $2,300 2020-06-05
Websphere Application Server HIGH 7.5
CVE-2020-4449

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-cr…

Fix: after 9.0.5.4
Fix from $1,950 2020-06-05
Websphere Application Server CRITICAL 9.8
CVE-2020-4450EPSS 34%

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-craft…

Fix: 8.5.5.18 / 9.0.5.5+
Fix from $2,300 2020-06-05
Serialize Javascript HIGH 8.1
CVE-2020-7660

serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".

Fix: 3.1.0+
Fix from $1,950 2020-06-01
Firefox CRITICAL 9.8
CVE-2020-12390

Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.

Fix: 76.0+
Fix from $2,300 2020-05-26
Unified Contact Center Express CRITICAL 9.8
CVE-2020-3280EPSS 7%

A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote …

Fix: 12.0+
Fix from $2,300 2020-05-22
Hive CRITICAL 9.8
CVE-2018-21234EPSS 8%

Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.

Fix: 5.0.4+
Fix from $2,300 2020-05-21
Tomcat HIGH 7.0
CVE-2020-9484EPSS 57%

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to contr…

Fix: 7.0.108 / 8.5.63+
Fix from $1,950 2020-05-20
Readyapi CRITICAL 9.8
CVE-2020-12835EPSS 13%

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attack…

No fix yet
Fix from $2,300 2020-05-20
Pandas CRITICAL 9.8
CVE-2020-13091

pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an…

Fix: after 1.0.3
Fix from $2,300 2020-05-15
Scikit Learn CRITICAL 9.8
CVE-2020-13092

scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, i…

Fix: after 0.23.0
Fix from $2,300 2020-05-15
Camel CRITICAL 9.8
CVE-2020-11972EPSS 6%

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users…

Fix: after 8.2.2
Fix from $2,300 2020-05-14
Camel CRITICAL 9.8
CVE-2020-11973EPSS 7%

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh…

Fix: after 8.5.0
Fix from $2,300 2020-05-14
TYPO3 HIGH 8.8
CVE-2020-11067

In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to in…

Fix: after 10.4.1
Fix from $1,950 2020-05-14
Eagle HIGH 8.8
CVE-2019-16112EPSS 11%

TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceMana…

No fix yet
Fix from $1,950 2020-05-13
Opennms Horizon HIGH 8.8
CVE-2020-12760

An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration …

Fix: 26.1.0 / 2018.1.19+
Fix from $1,950 2020-05-11
Media Server HIGH 7.2
CVE-2020-5741 KEVEPSS 73%

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

Fix: 1.19.3+
Fix from $1,950 2020-05-08