CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,844 vulnerabilities with CWE-502
CVE-2019-17531
CRITICAL
jackson-databind 2.0.0-2.9.10 - Remote Code Execution via Polymorphic Typing with Log4j JNDI
CVSS 9.8
CVE-2019-17267
CRITICAL
FasterXML jackson-databind < 2.9.10 - Deserialization of Untrusted Data via EhcacheJtaTransactionManagerLookup
CVSS 9.8
CVE-2019-17206
CRITICAL
Redis Wrapper < 0.3.0 - Remote Code Execution via Pickle Deserialization
CVSS 9.8
CVE-2019-16891
CRITICAL
Liferay Portal CE 6.2.5 - Code Injection
CVSS 9.8
CVE-2019-12630
CRITICAL
Cisco Security Manager < 4.18 - Unauthenticated Remote Code Execution via Java Deserialization
CVSS 9.8
CVE-2019-17080
HIGH
mintinstall 7.9.9 - Remote Code Execution via Untrusted REVIEWS_CACHE Deserialization
CVSS 7.8
CVE-2019-16943
CRITICAL
jackson-databind 2.0.0-2.9.10 - Remote Code Execution via P6Spy Default Typing
CVSS 9.8
CVE-2019-16942
CRITICAL
jackson-databind 2.0.0-2.9.10 - Remote Code Execution via Polymorphic Typing
CVSS 9.8
CVE-2019-10202
CRITICAL
JBoss Enterprise Application Platform - Deserialization of Untrusted Data via Jackson Mapper
CVSS 9.8
CVE-2019-9373
MEDIUM
Android 10 - Local Denial of Service via JobStore Deserialization Mismatch
CVSS 5.5
CVE-2019-9365
CRITICAL
Android 10 - Remote Code Execution via Bluetooth Deserialization Error
CVSS 9.8
CVE-2019-16894
CRITICAL
inoERP 4.15 - SQL Injection via Insecure Deserialization in download.php
CVSS 9.8
CVE-2019-16755
CRITICAL
BMC MyIT Digital Workplace < 18.08.00 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2019-11666
HIGH
Micro Focus Service Manager <9.63 - Deserialization
CVSS 8.8
CVE-2019-0195
CRITICAL
Apache Tapestry 5.4.0-5.4.2 and 5.4.0-5.4.4 - Remote Code Execution via Classpath Asset File URL Manipulation
CVSS 9.8
CVE-2019-16335
CRITICAL
FasterXML jackson-databind <2.9.10 - Info Disclosure
CVSS 9.8
CVE-2019-14540
CRITICAL
FasterXML jackson-databind <2.9.10 - Info Disclosure
CVSS 9.8
CVE-2019-16317
HIGH
pimcore < 5.7.1 - Authenticated Remote Code Execution via PHAR Deserialization
CVSS 8.8
CVE-2019-0189
CRITICAL
Apache OFBiz 16.11.01-16.11.05 - Remote Code Execution via HttpEngine ServiceContext Deserialization
CVSS 9.8
CVE-2019-14224
HIGH
Alfresco Community Edition 5.2 - RCE
CVSS 7.2
CVE-2019-5069
HIGH
Epignosis eFront LMS <5.2.12 - Code Injection
CVSS 8.8
CVE-2019-15780
CRITICAL
Formidable Form Builder < 4.02.01 - Deserialization of Untrusted Data
CVSS 9.8
CVE-2019-15521
CRITICAL
Spoon Library < 2014-02-06 and Fork CMS < 1.4.1 - PHP Object Injection via Cookie
CVSS 9.8
CVE-2019-11030
CRITICAL
Mirasys VMS < 7.6.1 and 8.x < 8.3.2 - Remote Code Execution via Insecure Deserialization in AuditTrailService
CVSS 9.8
CVE-2019-15321
CRITICAL
Optiontree < 2.7.3 - Insecure Deserialization
CVSS 9.8
Details
Vulnerabilities
2,844
Exploit Likelihood
Medium