Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

3,025 CVEs tagged with CWE-5021,168 Critical, 1,450 High, 335 Medium, 72 Low, 0 Unrated.

CVE-2016-9865

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x ver…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6620

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-5019

Published Oct 3, 2016

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserial…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4385

Published Sep 29, 2016

The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a cr…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6330

Published Sep 27, 2016

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-7124

Published Sep 12, 2016

ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possib…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1114

Published May 11, 2016

Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, rela…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-7450

Published Jan 2, 2016

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed

CVE-2015-6420

Published Dec 15, 2015

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Con…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-4271

Published Oct 10, 2013

The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1465

Published Feb 8, 2013

The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping para…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3527

Published Sep 5, 2012

view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrar…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0911

Published Jul 12, 2012

TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/ban…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3258

Published Sep 7, 2010

The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attack vectors.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1701

Published Mar 27, 2007

PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, whi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0791

Published Oct 7, 2003

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaS…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,001-3,025 of 3,025 CVEsPage 121 of 121