Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.8 CVE-2026-1462 A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin… Openshift Ai 2.25.7+ Fix from $1,9502026-04-13 HIGH 8.8 CVE-2026-32590 A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,9502026-04-08 HIGH 8.8 CVE-2022-1415 A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a… Decision Manager Mitigation only Fix from $1,9502023-09-11 HIGH 8.1 CVE-2021-4125 It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J… Openshift 4.6.52 / 4.7.40+ Fix from $1,9502022-08-24 MEDIUM 6.7 CVE-2021-4178 A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configure… Fabric8 Kubernetes 5.0.3 / 5.1.2+ Fix from $1,6002022-08-24 HIGH 7.2 CVE-2021-20318 The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502021-12-23 MEDIUM 6.6 CVE-2021-42550 In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configurat… Satellite 1.0.3+ Fix from $1,6002021-12-16 HIGH 7.8 CVE-2020-10721 A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configur… Fabric8 Maven after 4.4.1 Fix from $1,9502020-10-22 HIGH 7.5 CVE-2020-10740 A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application… Wildfly 20.0.0+ Fix from $1,9502020-06-22 CRITICAL 9.8 CVE-2019-14892EPSS 6% A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal… Decision Manager 2.6.7.3 / 2.8.11.5+ Fix from $2,3002020-03-02 HIGH 8.1 CVE-2020-2604 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE… Enterprise Linux after 13.0.1 Fix from $1,9502020-01-15 CRITICAL 9.8 CVE-2014-3699 eDeploy has RCE via cPickle deserialization of untrusted data Edeploy No fix yet Fix from $2,3002019-12-15 CRITICAL 9.8 CVE-2019-10202EPSS 5% A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002019-10-01 CRITICAL 9.8 CVE-2018-11307EPSS 6% An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows… Openshift Container Platform 2.6.7.3 / 2.7.9.4+ Fix from $2,3002019-07-09 HIGH 7.5 CVE-2018-10911 A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read… Virtualization Host 3.12.14 / 4.1.8+ Fix from $1,9502018-09-04 HIGH 7.2 CVE-2016-8648 It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX opera… Jboss A Mq Mitigation only Fix from $1,9502018-08-01 MEDIUM 5.3 CVE-2016-8653 It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this … Jboss A Mq Mitigation only Fix from $1,6002018-08-01 HIGH 8.8 CVE-2018-1131 Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat… Jboss Data Grid Mitigation only Fix from $1,9502018-05-15 MEDIUM 5.3 CVE-2016-9585 Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. … Jboss Enterprise Application Platform Mitigation only Fix from $1,6002018-03-09 HIGH 8.1 CVE-2018-1051 It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam… Resteasy Mitigation only Fix from $1,9502018-01-25 CRITICAL 9.8 CVE-2015-7501EPSS 83% Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pl… Data Grid Mitigation only Fix from $2,3002017-11-09 CRITICAL 9.8 CVE-2017-12149 KEVEPSS 91% In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002017-10-04 CRITICAL 9.8 CVE-2016-7050 SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R… Enterprise Linux Desktop Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2016-3690EPSS 5% The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload. Jboss Enterprise Application Platform Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2017-7504EPSS 29% HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se… Jboss Enterprise Application Platform after 4.0 Fix from $2,3002017-05-19 CRITICAL 9.8 CVE-2017-5929EPSS 8% QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components. Satellite 1.2.0+ Fix from $2,3002017-03-13 HIGH 8.8 CVE-2016-7065EPSS 12% The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos… Jboss Enterprise Application Platform No fix yet Fix from $1,9502016-10-13 CRITICAL 9.8 CVE-2016-6330EPSS 11% The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a… Jboss Operations Network Mitigation only Fix from $2,3002016-09-27 CRITICAL 9.8 CVE-2015-8103EPSS 87% The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J… Openshift Container Platform 1.625.2 / 1.638+ Fix from $2,3002015-11-25 HIGH 7.8 CVE-2011-2520 fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the bac… System Config Firewall after 1.2.29 Fix from $1,9502011-07-21