Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2016-9865 An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnseria… phpMyAdmin Patch available Fix from $2,3002016-12-11 CRITICAL 9.8 CVE-2016-6620 An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. Th… phpMyAdmin Patch available Fix from $2,3002016-12-11 HIGH 8.8 CVE-2016-7065EPSS 12% The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos… Jboss Enterprise Application Platform No fix yet Fix from $1,9502016-10-13 CRITICAL 9.8 CVE-2016-5019EPSS 8% CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow… Myfaces Trinidad 1.0.13 / 1.2.15+ Fix from $2,3002016-10-03 HIGH 7.3 CVE-2016-4385 The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execu… Network Automation Mitigation only Fix from $1,9502016-09-29 CRITICAL 9.8 CVE-2016-6330EPSS 11% The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a… Jboss Operations Network Mitigation only Fix from $2,3002016-09-27 HIGH 7.2 CVE-2016-4978EPSS 7% The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache Ac… Artemis 1.4.0+ Fix from $1,9502016-09-27 CRITICAL 9.8 CVE-2016-7124EPSS 17% ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause… PHP after 5.6.24 Fix from $2,3002016-09-12 CRITICAL 9.8 CVE-2016-1114EPSS 9% Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafte… Coldfusion Mitigation only Fix from $2,3002016-05-11 CRITICAL 9.8 CVE-2015-7450 KEVEPSS 98% Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote … Sterling B2b Integrator after 10.0.0.2 Fix from $2,3002016-01-02 CRITICAL 9.8 CVE-2015-6420EPSS 18% Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and… Commons Collections 3.2.2+ Fix from $2,3002015-12-15 CRITICAL 9.8 CVE-2015-8103EPSS 87% The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J… Openshift Container Platform 1.625.2 / 1.638+ Fix from $2,3002015-11-25 CRITICAL 9.8 CVE-2015-4852 KEVEPSS 96% The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands… Virtual Desktop Infrastructure after 3.5.2 Fix from $2,3002015-11-18 HIGH 7.5 CVE-2013-4271 The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote … Restlet after 2.1.3 Fix from $1,9502013-10-10 CRITICAL 9.8 CVE-2013-1465EPSS 7% The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objec… Cubecart after 5.2.0 Fix from $2,3002013-02-08 CRITICAL 9.8 CVE-2012-4406EPSS 7% OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memca… Fedora 1.7.0+ Fix from $2,3002012-10-22 CRITICAL 9.8 CVE-2012-0911EPSS 63% TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1)… Tikiwiki Cms\/groupware 6.7 / 8.4+ Fix from $2,3002012-07-12 MEDIUM 6.8 CVE-2011-2894EPSS 9% Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects fr… Spring Framework after 3.0.5 Fix from $1,6002011-10-04 HIGH 7.8 CVE-2011-2520 fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the bac… System Config Firewall after 1.2.29 Fix from $1,9502011-07-21 HIGH 7.5 CVE-2010-4574 The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not… Chrome 8.0.552.224 / 8.0.552.343+ Fix from $1,9502010-12-22 HIGH 9.3 CVE-2010-3258 The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attac… Chrome 6.0.472.53+ Fix from $1,9502010-09-07 CRITICAL 9.8 CVE-2003-0791 The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as … Mozilla after 1.4 Fix from $2,3002003-10-07