Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2021-12-22 CVE-2021-44029 Deserialization of Untrusted Data vulnerability in Quest Kace Desktop Authority
An issue was discovered in Quest KACE Desktop Authority before 11.2.
network
low complexity
quest CWE-502
critical
9.8
2021-12-21 CVE-2021-36336 Deserialization of Untrusted Data vulnerability in Dell Wyse Management Suite
Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.
network
low complexity
dell CWE-502
critical
9.8
2021-12-16 CVE-2021-42550 Deserialization of Untrusted Data vulnerability in multiple products
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
network
high complexity
qos redhat netapp siemens CWE-502
6.6
2021-12-15 CVE-2021-0970 Deserialization of Untrusted Data vulnerability in Google Android
In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch.
local
low complexity
google CWE-502
7.8
2021-12-14 CVE-2021-4104 Deserialization of Untrusted Data vulnerability in multiple products
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration.
network
high complexity
apache fedoraproject redhat oracle CWE-502
7.5
2021-12-13 CVE-2021-24857 Deserialization of Untrusted Data vulnerability in Nocean Totop Link
The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.
network
low complexity
nocean CWE-502
critical
9.8
2021-12-10 CVE-2021-44228 Deserialization of Untrusted Data vulnerability in multiple products
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints.
10.0
2021-12-07 CVE-2021-42127 Deserialization of Untrusted Data vulnerability in Ivanti Avalanche
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
network
low complexity
ivanti CWE-502
critical
9.8
2021-12-07 CVE-2021-42130 Deserialization of Untrusted Data vulnerability in Ivanti Avalanche
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
network
low complexity
ivanti CWE-502
8.8
2021-12-06 CVE-2021-44677 Deserialization of Untrusted Data vulnerability in Veritas Enterprise Vault
An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2.
network
low complexity
veritas CWE-502
critical
9.8