Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2018-8021EPSS 53% Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. … Superset 0.23+ Fix from $2,3002018-11-07 CRITICAL 9.8 CVE-2018-8018EPSS 7% In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deseriali… Ignite 2.4.8 / 2.5.3+ Fix from $2,3002018-07-20 CRITICAL 9.8 CVE-2018-8013EPSS 19% In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w… Batik 1.10 / 7.2+ Fix from $2,3002018-05-24 HIGH 7.5 CVE-2018-1310 Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE… Nifi 1.6.0+ Fix from $1,9502018-05-23 CRITICAL 9.8 CVE-2018-1295EPSS 6% In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i… Ignite after 2.3.0 Fix from $2,3002018-04-02 CRITICAL 9.8 CVE-2017-15692 In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce… Geode 1.4.0+ Fix from $2,3002018-02-27 HIGH 7.5 CVE-2017-15693 In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause t… Geode 1.4.0+ Fix from $1,9502018-02-27 MEDIUM 5.0 CVE-2017-15703 Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den… Nifi after 1.4.0 Fix from $1,6002018-01-25 CRITICAL 9.8 CVE-2016-6814EPSS 17% When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se… Groovy after 2.4.7 Fix from $2,3002018-01-18 CRITICAL 9.8 CVE-2017-5641EPSS 21% Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. … Flex Blazeds 8.5.3-00+ Fix from $2,3002017-12-28 CRITICAL 9.8 CVE-2017-12633EPSS 7% The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. D… Camel 2.19.4 / 2.20.1+ Fix from $2,3002017-11-15 CRITICAL 9.8 CVE-2017-12634EPSS 7% The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De… Camel 2.19.4+ Fix from $2,3002017-11-15 CRITICAL 9.8 CVE-2016-5003EPSS 15% The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ… Ws Xmlrpc No fix yet Fix from $2,3002017-10-27 HIGH 7.8 CVE-2017-12628 The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to ex… James Server after 3.0.0 Fix from $1,9502017-10-20 CRITICAL 9.8 CVE-2016-8736 Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. Openmeetings 3.1.2+ Fix from $2,3002017-10-12 HIGH 8.1 CVE-2017-9805 KEVEPSS 99% The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for des… Struts 2.3.34 / 2.5.13+ Fix from $1,9502017-09-15 HIGH 8.8 CVE-2016-8744 Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal… Brooklyn after 0.9.0 Fix from $1,9502017-09-13 HIGH 7.8 CVE-2017-12612 In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched … Spark Mitigation only Fix from $1,9502017-09-13 CRITICAL 9.1 CVE-2016-6793EPSS 8% The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop… Wicket 1.5.17 / 6.25.0+ Fix from $2,3002017-07-17 CRITICAL 9.8 CVE-2017-5645EPSS 90% In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a … Log4j 2.8.2+ Fix from $2,3002017-04-17 CRITICAL 9.8 CVE-2016-0779EPSS 10% The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted s… Tomee after 1.7.3 Fix from $2,3002017-04-11 CRITICAL 9.8 CVE-2016-6809EPSS 8% Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d… Nutch after 1.13 Fix from $2,3002017-04-06 CRITICAL 9.8 CVE-2016-8749EPSS 11% Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks. Camel No fix yet Fix from $2,3002017-03-28 CRITICAL 9.8 CVE-2017-3159EPSS 6% Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to secur… Camel after 2.18.1 Fix from $2,3002017-03-07 CRITICAL 9.8 CVE-2016-5019EPSS 8% CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow… Myfaces Trinidad 1.0.13 / 1.2.15+ Fix from $2,3002016-10-03 HIGH 7.2 CVE-2016-4978EPSS 7% The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache Ac… Artemis 1.4.0+ Fix from $1,9502016-09-27 CRITICAL 9.8 CVE-2015-6420EPSS 18% Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and… Commons Collections 3.2.2+ Fix from $2,3002015-12-15