Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2023-06-28 CVE-2023-21205 Deserialization of Untrusted Data vulnerability in Google Android 13.0
In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization.
local
low complexity
google CWE-502
5.5
2023-06-28 CVE-2023-21206 Deserialization of Untrusted Data vulnerability in Google Android 13.0
In initiateVenueUrlAnqpQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization.
local
low complexity
google CWE-502
4.4
2023-06-28 CVE-2023-21209 Deserialization of Untrusted Data vulnerability in Google Android 13.0
In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization.
local
low complexity
google CWE-502
6.7
2023-06-23 CVE-2023-33299 Deserialization of Untrusted Data vulnerability in Fortinet Fortinac
A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port.
network
low complexity
fortinet CWE-502
critical
9.8
2023-06-20 CVE-2023-26436 Deserialization of Untrusted Data vulnerability in Open-Xchange Appsuite Backend
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization.
low complexity
open-xchange CWE-502
8.8
2023-06-19 CVE-2023-35839 Deserialization of Untrusted Data vulnerability in Solon
A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
network
low complexity
solon CWE-502
critical
9.8
2023-06-18 CVE-2023-3308 Deserialization of Untrusted Data vulnerability in Whaleal Icefrog 1.1.8
A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8.
network
low complexity
whaleal CWE-502
8.8
2023-06-15 CVE-2023-21124 Deserialization of Untrusted Data vulnerability in Google Android
In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization.
local
low complexity
google CWE-502
7.8
2023-06-14 CVE-2023-3001 Deserialization of Untrusted Data vulnerability in Schneider-Electric Igss Dashboard 16.0.0.23040/16.0.0.23130
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.
local
low complexity
schneider-electric CWE-502
7.8
2023-06-14 CVE-2023-3234 Deserialization of Untrusted Data vulnerability in Crmeb
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0.
network
low complexity
crmeb CWE-502
critical
9.8