Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Jenkins HIGH 8.8
CVE-2017-2608EPSS 6%

Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.i…

Fix: 2.32.2+
Fix from $1,950 2018-05-15
Jboss Data Grid HIGH 8.8
CVE-2018-1131

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat…

Mitigation only
Fix from $1,950 2018-05-15
Windows 10 1507 HIGH 8.8
CVE-2018-0824 KEVEPSS 72%

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM f…

Patch available
Fix from $1,950 2018-05-09
Xprotect HIGH 8.1
CVE-2018-7891

The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contain…

Fix: 10.0a / 10.1a+
Fix from $1,950 2018-04-30
Weblogic Server CRITICAL 9.8
CVE-2018-2628 KEVEPSS 99%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are af…

Patch available
Fix from $2,300 2018-04-19
Suricata Update HIGH 7.8
CVE-2018-1000167

OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following f…

No fix yet
Fix from $1,950 2018-04-18
Cms Made Simple CRITICAL 9.8
CVE-2018-10085

CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\c…

Fix: after 2.2.6
Fix from $2,300 2018-04-13
Password Vault CRITICAL 9.8
CVE-2018-9843EPSS 17%

The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serializ…

Fix: 9.9.5 / 10.1+
Fix from $2,300 2018-04-12
Android HIGH 7.8
CVE-2017-13286

In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a l…

Mitigation only
Fix from $1,950 2018-04-04
Ignite CRITICAL 9.8
CVE-2018-1295EPSS 6%

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i…

Fix: after 2.3.0
Fix from $2,300 2018-04-02
Myscript CRITICAL 9.8
CVE-2015-2020

The MyScript SDK before 1.3 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that …

Fix: 1.3+
Fix from $2,300 2018-03-29
Db2 HIGH 7.8
CVE-2017-1677

IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.b…

Mitigation only
Fix from $1,950 2018-03-22
Pi Data Archive HIGH 7.5
CVE-2018-7529

A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deseria…

Fix: after 2017
Fix from $1,950 2018-03-14
Rubygems HIGH 7.8
CVE-2018-1000074

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,950 2018-03-13
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2016-9585

Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. …

Mitigation only
Fix from $1,600 2018-03-09
Calibre HIGH 7.8
CVE-2018-7889

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code …

Patch available
Fix from $1,950 2018-03-08
Secure Access Control System CRITICAL 9.8
CVE-2018-0147 KEVEPSS 18%

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated,…

Mitigation only
Fix from $2,300 2018-03-08
Geode CRITICAL 9.8
CVE-2017-15692

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce…

Fix: 1.4.0+
Fix from $2,300 2018-02-27
Geode HIGH 7.5
CVE-2017-15693

In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause t…

Fix: 1.4.0+
Fix from $1,950 2018-02-27
Debian Linux CRITICAL 9.8
CVE-2018-7489EPSS 20%

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an in…

Fix: 2.7.9.3 / 2.8.11.1+
Fix from $2,300 2018-02-26
Intelligent Management Center HIGH 8.8
CVE-2017-8962

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun…

No fix yet
Fix from $1,950 2018-02-15
Intelligent Management Center HIGH 8.8
CVE-2017-8963

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun…

Mitigation only
Fix from $1,950 2018-02-15
Intelligent Management Center HIGH 8.8
CVE-2017-8964

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun…

Mitigation only
Fix from $1,950 2018-02-15
Intelligent Management Center HIGH 8.8
CVE-2017-8965

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun…

No fix yet
Fix from $1,950 2018-02-15
Intelligent Management Center HIGH 8.8
CVE-2017-8966

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun…

Mitigation only
Fix from $1,950 2018-02-15
Intelligent Management Center HIGH 8.8
CVE-2017-8967

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun…

Mitigation only
Fix from $1,950 2018-02-15
Intelligent Management Center CRITICAL 9.8
CVE-2017-12558EPSS 38%

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

Fix: after 7.3
Fix from $2,300 2018-02-15
Intelligent Management Center CRITICAL 9.8
CVE-2017-5790EPSS 18%

A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

Mitigation only
Fix from $2,300 2018-02-15
Intelligent Management Center CRITICAL 9.8
CVE-2017-5792EPSS 34%

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

No fix yet
Fix from $2,300 2018-02-15
Intelligent Management Center CRITICAL 9.8
CVE-2017-12556EPSS 38%

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

Fix: after 7.3
Fix from $2,300 2018-02-15