Vulnerability index

Browse CVEs

73 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Debian Linux CRITICAL 9.8
CVE-2018-19362EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core cla…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux HIGH 7.2
CVE-2018-19274EPSS 5%

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deseria…

Fix: 3.2.4+
Fix from $1,950 2018-11-17
Debian Linux HIGH 8.8
CVE-2018-19296

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

Fix: 5.2.27 / 6.0.6+
Fix from $1,950 2018-11-16
Debian Linux CRITICAL 9.8
CVE-2018-7489EPSS 20%

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an in…

Fix: 2.7.9.3 / 2.8.11.1+
Fix from $2,300 2018-02-26
Debian Linux CRITICAL 9.8
CVE-2017-15095EPSS 8%

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfo…

Fix: 2.6.7.2 / 2.7.9.2+
Fix from $2,300 2018-02-06
Debian Linux CRITICAL 9.8
CVE-2017-7525EPSS 38%

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user …

Fix: 2.6.7.1 / 2.7.9.1+
Fix from $2,300 2018-02-06
Debian Linux HIGH 8.1
CVE-2018-5968EPSS 7%

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…

Fix: 2.6.7.3 / 2.7.9.2+
Fix from $1,950 2018-01-22
Debian Linux CRITICAL 9.8
CVE-2017-17485EPSS 50%

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…

Fix: 2.6.7.3 / 2.7.9.2+
Fix from $2,300 2018-01-10
Debian Linux CRITICAL 9.8
CVE-2017-0903EPSS 16%

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specificatio…

Patch available
Fix from $2,300 2017-10-11
Debian Linux CRITICAL 9.8
CVE-2016-4000EPSS 6%

Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.

Patch available
Fix from $2,300 2017-07-06
Debian Linux HIGH 8.2
CVE-2017-2295

Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. …

Fix: after 4.10.0
Fix from $1,950 2017-07-05
Lintian HIGH 7.8
CVE-2017-8829

Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with …

Fix: after 2.5.50.3
Fix from $1,950 2017-05-08
Debian Linux HIGH 7.5
CVE-2016-4483EPSS 6%

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds rea…

Fix: 2.9.4+
Fix from $1,950 2017-04-11