Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
MEDIUM 6.5 CVE-2017-10803 In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database A… Odoo Patch available Fix from $1,6002017-07-04 CRITICAL 9.0 CVE-2017-2292 Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution … Mcollective after 2.10.3 Fix from $2,3002017-06-30 CRITICAL 9.8 CVE-2017-9830EPSS 6% Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it cr… Crashplan Mitigation only Fix from $2,3002017-06-27 CRITICAL 9.8 CVE-2017-9424 IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deseria… Breeze.server.net after 1.6.0 Fix from $2,3002017-06-22 CRITICAL 9.8 CVE-2016-7050EPSS 5% SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R… Enterprise Linux Desktop Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2016-3690EPSS 5% The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload. Jboss Enterprise Application Platform Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2017-5878 The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attack… Media Server Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2017-4914EPSS 9% VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote a… Vsphere Data Protection Patch available Fix from $2,3002017-06-07 CRITICAL 9.8 CVE-2017-9363 Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted auth… Iam after 1.7.4 Fix from $2,3002017-06-02 CRITICAL 9.8 CVE-2017-7504EPSS 29% HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se… Jboss Enterprise Application Platform after 4.0 Fix from $2,3002017-05-19 HIGH 7.8 CVE-2017-8829 Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with … Lintian after 2.5.50.3 Fix from $1,9502017-05-08 HIGH 7.5 CVE-2017-8804EPSS 8% The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remo… Glibc Patch available Fix from $1,9502017-05-07 CRITICAL 9.8 CVE-2017-3066 KEVEPSS 91% Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vuln… Coldfusion Patch available Fix from $2,3002017-04-27 HIGH 7.8 CVE-2017-7293 The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privile… Dolby Audio X2 No fix yet Fix from $1,9502017-04-26 CRITICAL 9.8 CVE-2017-5645EPSS 90% In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a … Log4j 2.8.2+ Fix from $2,3002017-04-17 CRITICAL 9.8 CVE-2016-0779EPSS 10% The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted s… Tomee after 1.7.3 Fix from $2,3002017-04-11 HIGH 7.5 CVE-2016-4483EPSS 6% The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds rea… Debian Linux 2.9.4+ Fix from $1,9502017-04-11 CRITICAL 9.8 CVE-2017-5983EPSS 16% The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers… Jira Mitigation only Fix from $2,3002017-04-10 MEDIUM 6.5 CVE-2016-10304 The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and ser… Netweaver Application Server Java Mitigation only Fix from $1,6002017-04-10 CRITICAL 9.8 CVE-2016-6809EPSS 8% Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d… Nutch after 1.13 Fix from $2,3002017-04-06 CRITICAL 9.8 CVE-2016-8749EPSS 11% Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks. Camel No fix yet Fix from $2,3002017-03-28 CRITICAL 9.8 CVE-2014-8731EPSS 12% PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of t… Phpmemcachedadmin after 1.2.2 Fix from $2,3002017-03-23 CRITICAL 9.8 CVE-2017-5929EPSS 8% QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components. Satellite 1.2.0+ Fix from $2,3002017-03-13 CRITICAL 9.8 CVE-2017-3159EPSS 6% Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to secur… Camel after 2.18.1 Fix from $2,3002017-03-07 CRITICAL 9.8 CVE-2017-5830 Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts. Revive Adserver after 4.0.0 Fix from $2,3002017-03-03 CRITICAL 9.8 CVE-2016-0360 IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malici… Websphere Mq Jms Mitigation only Fix from $2,3002017-02-15 CRITICAL 9.8 CVE-2017-5954 An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to a… Serialize To Js Patch available Fix from $2,3002017-02-10 CRITICAL 9.8 CVE-2017-5941EPSS 61% An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to ac… Node Serialize after 0.0.4 Fix from $2,3002017-02-09 CRITICAL 9.8 CVE-2016-6199 ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object. Gradle No fix yet Fix from $2,3002017-02-07 CRITICAL 9.1 CVE-2016-3415 Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276. Zimbra Collaboration Suite after 8.6.0 Fix from $2,3002017-01-18