Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Cryo CRITICAL 9.8
CVE-2018-3784

A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.

No fix yet
Fix from $2,300 2018-08-17
Windows 10 HIGH 8.8
CVE-2018-8349EPSS 23%

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM f…

Mitigation only
Fix from $1,950 2018-08-15
Openj9 HIGH 7.8
CVE-2018-12539

In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on th…

Patch available
Fix from $1,950 2018-08-14
Dotpeek HIGH 7.8
CVE-2018-14878

JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as…

Fix: 2018.2+
Fix from $1,950 2018-08-13
Laravel HIGH 8.1
CVE-2018-15133 KEVEPSS 77%

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially u…

Fix: after 5.6.29
Fix from $1,950 2018-08-09
Network Node Manager I HIGH 8.8
CVE-2016-4398

A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 1…

Mitigation only
Fix from $1,950 2018-08-06
Business Service Management HIGH 8.8
CVE-2016-4405

A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collection Java Deserialization ver…

Fix: after 9.26
Fix from $1,950 2018-08-06
Jboss A Mq HIGH 7.2
CVE-2016-8648

It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX opera…

Mitigation only
Fix from $1,950 2018-08-01
Jboss A Mq MEDIUM 5.3
CVE-2016-8653

It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this …

Mitigation only
Fix from $1,600 2018-08-01
Zxiptv Epg Firmware CRITICAL 9.8
CVE-2017-10934

All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (A…

Fix: 5.09.02.02t4+
Fix from $2,300 2018-07-25
Ignite CRITICAL 9.8
CVE-2018-8018EPSS 7%

In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deseriali…

Fix: 2.4.8 / 2.5.3+
Fix from $2,300 2018-07-20
Php Formmail Generator CRITICAL 9.8
CVE-2016-9483

The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthe…

Mitigation only
Fix from $2,300 2018-07-13
Manageengine Applications Manager CRITICAL 9.8
CVE-2016-9498EPSS 22%

ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by …

Mitigation only
Fix from $2,300 2018-07-13
Yamldotnet HIGH 7.8
CVE-2018-1000210

YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() …

Fix: after 4.3.2
Fix from $1,950 2018-07-13
Fedora CRITICAL 9.8
CVE-2017-18342EPSS 6%

In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in versio…

Fix: 5.1+
Fix from $2,300 2018-06-27
Openpsa CRITICAL 9.8
CVE-2018-1000525

openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request variables that can result in Possible information disclosure…

No fix yet
Fix from $2,300 2018-06-26
Froxlor HIGH 7.2
CVE-2018-1000527

Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and …

Fix: after 0.9.39.5
Fix from $1,950 2018-06-26
Redirection HIGH 7.2
CVE-2018-1000509

Redirection version 2.7.1 contains a Serialisation vulnerability possibly allowing ACE vulnerability in Settings page AJAX that can result in could a…

No fix yet
Fix from $1,950 2018-06-26
Universal Cmbd Browser HIGH 8.8
CVE-2018-6496

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which coul…

Fix: after 4.15.1
Fix from $1,950 2018-06-16
Cms Server HIGH 8.8
CVE-2018-6497

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10…

Fix: after 11.0
Fix from $1,950 2018-06-16
Graniteds HIGH 8.1
CVE-2017-3199EPSS 6%

The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 s…

No fix yet
Fix from $1,950 2018-06-11
Graniteds HIGH 8.1
CVE-2017-3200EPSS 6%

The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public param…

No fix yet
Fix from $1,950 2018-06-11
Flamingo Amf Serializer HIGH 8.1
CVE-2017-3201EPSS 5%

The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class instances from java.io.Externali…

No fix yet
Fix from $1,950 2018-06-11
Flamingo CRITICAL 9.8
CVE-2017-3202EPSS 8%

The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes …

No fix yet
Fix from $2,300 2018-06-11
Spring Flex HIGH 8.1
CVE-2017-3203EPSS 6%

The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 …

No fix yet
Fix from $1,950 2018-06-11
Weborb For Java CRITICAL 9.8
CVE-2017-3207EPSS 8%

The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externaliz…

No fix yet
Fix from $2,300 2018-06-11
Batik CRITICAL 9.8
CVE-2018-8013EPSS 19%

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…

Fix: 1.10 / 7.2+
Fix from $2,300 2018-05-24
Xenmobile Server HIGH 8.1
CVE-2018-10654

There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

Mitigation only
Fix from $1,950 2018-05-23
Nifi HIGH 7.5
CVE-2018-1310

Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE…

Fix: 1.6.0+
Fix from $1,950 2018-05-23
Coldfusion CRITICAL 9.8
CVE-2018-4939 KEVEPSS 63%

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vu…

Mitigation only
Fix from $2,300 2018-05-19