Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2019-05-14 CVE-2019-10924 Deserialization of Untrusted Data vulnerability in Siemens Logo! Soft Comfort
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.3).
network
siemens CWE-502
6.8
2019-05-09 CVE-2019-11831 Deserialization of Untrusted Data vulnerability in multiple products
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
network
low complexity
typo3 debian fedoraproject drupal joomla CWE-502
critical
9.8
2019-05-09 CVE-2019-11830 Deserialization of Untrusted Data vulnerability in Typo3 Pharstreamwrapper
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
network
low complexity
typo3 CWE-502
critical
9.8
2019-05-08 CVE-2019-11458 Deserialization of Untrusted Data vulnerability in Cakefoundation Cakephp 3.7.6
An issue was discovered in SmtpTransport in CakePHP 3.7.6.
network
low complexity
cakefoundation CWE-502
6.4
2019-05-06 CVE-2019-5434 Deserialization of Untrusted Data vulnerability in Revive-Sas Revive Adserver
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method.
network
low complexity
revive-sas CWE-502
7.5
2019-04-24 CVE-2019-7214 Deserialization of Untrusted Data vulnerability in Smartertools Smartermail
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data.
network
low complexity
smartertools CWE-502
critical
9.8
2019-04-11 CVE-2019-9056 Deserialization of Untrusted Data vulnerability in Cmsmadesimple CMS Made Simple 2.2.8
An issue was discovered in CMS Made Simple 2.2.8.
network
low complexity
cmsmadesimple CWE-502
6.5
2019-04-09 CVE-2019-7361 Deserialization of Untrusted Data vulnerability in Autodesk products
An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018.
network
autodesk CWE-502
6.8
2019-04-04 CVE-2019-10867 Deserialization of Untrusted Data vulnerability in Pimcore
An issue was discovered in Pimcore before 5.7.1.
network
low complexity
pimcore CWE-502
6.5
2019-04-02 CVE-2018-12680 Deserialization of Untrusted Data vulnerability in Coapthon Project Coapthon
The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a denial of service in applications that use this library (e.g., the standard CoAP server, CoAP client, CoAP reverse proxy, example collect CoAP server and client) when they receive crafted CoAP messages.
network
low complexity
coapthon-project CWE-502
5.0