Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2017-2608EPSS 6% Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.i… Jenkins 2.32.2+ Fix from $1,9502018-05-15 HIGH 8.8 CVE-2018-1131 Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat… Jboss Data Grid Mitigation only Fix from $1,9502018-05-15 HIGH 8.8 CVE-2018-0824 KEVEPSS 72% A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM f… Windows 10 1507 Patch available Fix from $1,9502018-05-09 HIGH 8.1 CVE-2018-7891 The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contain… Xprotect 10.0a / 10.1a+ Fix from $1,9502018-04-30 CRITICAL 9.8 CVE-2018-2628 KEVEPSS 99% Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are af… Weblogic Server Patch available Fix from $2,3002018-04-19 HIGH 7.8 CVE-2018-1000167 OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following f… Suricata Update No fix yet Fix from $1,9502018-04-18 CRITICAL 9.8 CVE-2018-10085 CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\c… Cms Made Simple after 2.2.6 Fix from $2,3002018-04-13 CRITICAL 9.8 CVE-2018-9843EPSS 17% The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serializ… Password Vault 9.9.5 / 10.1+ Fix from $2,3002018-04-12 HIGH 7.8 CVE-2017-13286 In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a l… Android Mitigation only Fix from $1,9502018-04-04 CRITICAL 9.8 CVE-2018-1295EPSS 6% In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i… Ignite after 2.3.0 Fix from $2,3002018-04-02 CRITICAL 9.8 CVE-2015-2020 The MyScript SDK before 1.3 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that … Myscript 1.3+ Fix from $2,3002018-03-29 HIGH 7.8 CVE-2017-1677 IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.b… Db2 Mitigation only Fix from $1,9502018-03-22 HIGH 7.5 CVE-2018-7529 A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deseria… Pi Data Archive after 2017 Fix from $1,9502018-03-14 HIGH 7.8 CVE-2018-1000074 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a… Rubygems after 2.5.0 Fix from $1,9502018-03-13 MEDIUM 5.3 CVE-2016-9585 Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. … Jboss Enterprise Application Platform Mitigation only Fix from $1,6002018-03-09 HIGH 7.8 CVE-2018-7889 gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code … Calibre Patch available Fix from $1,9502018-03-08 CRITICAL 9.8 CVE-2018-0147 KEVEPSS 18% A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated,… Secure Access Control System Mitigation only Fix from $2,3002018-03-08 CRITICAL 9.8 CVE-2017-15692 In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce… Geode 1.4.0+ Fix from $2,3002018-02-27 HIGH 7.5 CVE-2017-15693 In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause t… Geode 1.4.0+ Fix from $1,9502018-02-27 CRITICAL 9.8 CVE-2018-7489EPSS 20% FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an in… Debian Linux 2.7.9.3 / 2.8.11.1+ Fix from $2,3002018-02-26 HIGH 8.8 CVE-2017-8962 A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun… Intelligent Management Center No fix yet Fix from $1,9502018-02-15 HIGH 8.8 CVE-2017-8963 A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun… Intelligent Management Center Mitigation only Fix from $1,9502018-02-15 HIGH 8.8 CVE-2017-8964 A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun… Intelligent Management Center Mitigation only Fix from $1,9502018-02-15 HIGH 8.8 CVE-2017-8965 A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun… Intelligent Management Center No fix yet Fix from $1,9502018-02-15 HIGH 8.8 CVE-2017-8966 A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun… Intelligent Management Center Mitigation only Fix from $1,9502018-02-15 HIGH 8.8 CVE-2017-8967 A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was foun… Intelligent Management Center Mitigation only Fix from $1,9502018-02-15 CRITICAL 9.8 CVE-2017-12558EPSS 38% A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. Intelligent Management Center after 7.3 Fix from $2,3002018-02-15 CRITICAL 9.8 CVE-2017-5790EPSS 18% A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found. Intelligent Management Center Mitigation only Fix from $2,3002018-02-15 CRITICAL 9.8 CVE-2017-5792EPSS 34% A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found. Intelligent Management Center No fix yet Fix from $2,3002018-02-15 CRITICAL 9.8 CVE-2017-12556EPSS 38% A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. Intelligent Management Center after 7.3 Fix from $2,3002018-02-15