Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-9865
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnseria…
phpMyAdmin
Patch available
CRITICAL 9.8
CVE-2016-6620
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. Th…
phpMyAdmin
Patch available
HIGH 8.8
CVE-2016-7065EPSS 12%
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos…
Jboss Enterprise Application Platform
No fix yet
CRITICAL 9.8
CVE-2016-5019EPSS 8%
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow…
Myfaces Trinidad
1.0.13 / 1.2.15+
HIGH 7.3
CVE-2016-4385
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execu…
Network Automation
Mitigation only
CRITICAL 9.8
CVE-2016-6330EPSS 11%
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…
Jboss Operations Network
Mitigation only
HIGH 7.2
CVE-2016-4978EPSS 7%
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache Ac…
Artemis
1.4.0+
CRITICAL 9.8
CVE-2016-7124EPSS 17%
ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause…
PHP
after 5.6.24
CRITICAL 9.8
CVE-2016-1114EPSS 9%
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafte…
Coldfusion
Mitigation only
CRITICAL 9.8
CVE-2015-7450 KEVEPSS 98%
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote …
Sterling B2b Integrator
after 10.0.0.2
CRITICAL 9.8
CVE-2015-6420EPSS 18%
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and…
Commons Collections
3.2.2+
CRITICAL 9.8
CVE-2015-8103EPSS 87%
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J…
Openshift Container Platform
1.625.2 / 1.638+
CRITICAL 9.8
CVE-2015-4852 KEVEPSS 96%
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands…
Virtual Desktop Infrastructure
after 3.5.2
HIGH 7.5
CVE-2013-4271
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote …
Restlet
after 2.1.3
CRITICAL 9.8
CVE-2013-1465EPSS 7%
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objec…
Cubecart
after 5.2.0
CRITICAL 9.8
CVE-2012-4406EPSS 7%
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memca…
Fedora
1.7.0+
CRITICAL 9.8
CVE-2012-0911EPSS 63%
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1)…
Tikiwiki Cms\/groupware
6.7 / 8.4+
MEDIUM 6.8
CVE-2011-2894EPSS 9%
Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects fr…
Spring Framework
after 3.0.5
HIGH 7.8
CVE-2011-2520
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the bac…
System Config Firewall
after 1.2.29
HIGH 7.5
CVE-2010-4574
The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not…
Chrome
8.0.552.224 / 8.0.552.343+
HIGH 9.3
CVE-2010-3258
The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attac…
Chrome
6.0.472.53+
CRITICAL 9.8
CVE-2003-0791
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as …
Mozilla
after 1.4