Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2019-03-06 CVE-2019-0187 Deserialization of Untrusted Data vulnerability in Apache Jmeter 4.0/5.0
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options).
network
low complexity
apache CWE-502
critical
9.8
2019-02-27 CVE-2019-9212 Deserialization of Untrusted Data vulnerability in Antfin Sofa-Hessian
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget.
network
low complexity
antfin CWE-502
critical
9.8
2019-02-21 CVE-2019-6340 Deserialization of Untrusted Data vulnerability in Drupal
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10.
network
high complexity
drupal CWE-502
8.1
2019-02-04 CVE-2019-1000005 Deserialization of Untrusted Data vulnerability in Mpdf Project Mpdf
mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc..
network
low complexity
mpdf-project CWE-502
8.8
2019-01-22 CVE-2019-6503 Deserialization of Untrusted Data vulnerability in Chatopera Cosin 3.10.0
There is a deserialization vulnerability in Chatopera cosin v3.10.0.
network
low complexity
chatopera CWE-502
critical
9.8
2019-01-22 CVE-2019-6338 Deserialization of Untrusted Data vulnerability in multiple products
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library.
network
low complexity
drupal debian CWE-502
8.0
2019-01-17 CVE-2018-20732 Deserialization of Untrusted Data vulnerability in SAS web Infrastructure Platform 9.4
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
network
low complexity
sas CWE-502
critical
9.8
2019-01-16 CVE-2019-6446 Deserialization of Untrusted Data vulnerability in multiple products
An issue was discovered in NumPy 1.16.0 and earlier.
network
low complexity
numpy fedoraproject CWE-502
critical
9.8
2019-01-15 CVE-2018-20718 Deserialization of Untrusted Data vulnerability in Pydio
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference.
network
low complexity
pydio CWE-502
critical
9.8
2019-01-09 CVE-2018-6162 Deserialization of Untrusted Data vulnerability in multiple products
Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian redhat CWE-502
8.8