CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,137 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 1 of 63
- CVE-2003-0791CRITICALCVSS 9.8EG 9.82003-10-07
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
- CVE-2005-2875HIGHCVSS v2 7.5EG 7.52005-09-13
Py2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes.
- CVE-2007-1701MEDIUMCVSS v2 6.8EG 6.82007-03-27
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by…
- CVE-2010-3258HIGHCVSS v2 9.3EG 9.32010-09-07
The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attack vectors.
- CVE-2010-4574HIGHCVSS v2 7.5EG 7.52010-12-22
The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message dese…
- CVE-2011-2520HIGHCVSS 7.8EG 7.82011-07-21
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
- CVE-2013-4521CRITICALCVSS 9.8EG 9.82020-02-06
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serializ…
- CVE-2013-7489MEDIUMCVSS 6.8EG 6.82020-06-26
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
- CVE-2014-1420LOWCVSS 3.8EG 3.82020-09-11
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to lau…
- CVE-2014-1860CRITICALCVSS 9.8EG 9.82020-01-08
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
- CVE-2014-3699CRITICALCVSS 9.8EG 9.82019-12-15
eDeploy has RCE via cPickle deserialization of untrusted data
- CVE-2014-8731CRITICALCVSS 9.8EG 9.82017-03-23
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.
- CVE-2014-9515CRITICALCVSS 9.8EG 9.82017-12-29
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.
- CVE-2015-2020CRITICALCVSS 9.8EG 9.82018-03-29
The MyScript SDK before 1.3 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
- CVE-2015-4852CRITICALCVSS 9.8EG 9.8⚠ KEV2015-11-18
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to …
- CVE-2015-5164HIGHCVSS 7.2EG 7.22017-10-18
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message, related to a pic…
- CVE-2015-7450CRITICALCVSS 9.8EG 9.8⚠ KEV2016-01-02
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t…
- CVE-2015-7501CRITICALCVSS 9.8EG 9.82017-11-09
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JB…
- CVE-2016-0360CRITICALCVSS 9.8EG 9.82017-02-15
IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM…
- CVE-2016-0750HIGHCVSS 4.2EG 8.82018-09-11
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote c…
- CVE-2016-0779CRITICALCVSS 9.8EG 9.82017-04-11
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.
- CVE-2016-1000027CRITICALCVSS 9.8EG 9.82020-01-02
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occu…
- CVE-2016-10304MEDIUMCVSS 6.5EG 6.52017-04-10
The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka…
- CVE-2016-10750HIGHCVSS 8.1EG 8.12019-05-22
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the c…
- CVE-2016-10753HIGHCVSS 8.8EG 8.82019-05-24
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
- CVE-2016-1114CRITICALCVSS 9.8EG 9.82016-05-11
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
- CVE-2016-1487HIGHCVSS 8.8EG 8.82020-03-09
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
- CVE-2016-15044CRITICALCVSS 9.3EG 9.32025-07-23
A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sendin…
- CVE-2016-3415CRITICALCVSS 9.1EG 9.12017-01-18
Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.
- CVE-2016-3690CRITICALCVSS 9.8EG 9.82017-06-08
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
- CVE-2016-3957CRITICALCVSS 9.8EG 9.82018-02-06
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowledge of encryption_k…
- CVE-2016-4000CRITICALCVSS 9.8EG 9.82017-07-06
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
- CVE-2016-4385HIGHCVSS 7.3EG 7.32016-09-29
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons …
- CVE-2016-4398HIGHCVSS 8.8EG 8.82018-08-06
A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10 using Java Deserialization.
- CVE-2016-4405HIGHCVSS 8.8EG 8.82018-08-06
A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collection Java Deserialization versions v9.20-v9.26
- CVE-2016-4483HIGHCVSS 7.5EG 7.52017-04-11
The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE:…
- CVE-2016-4978HIGHCVSS 7.2EG 7.22016-09-27
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send…
- CVE-2016-5003CRITICALCVSS 9.8EG 9.82017-10-27
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
- CVE-2016-5019CRITICALCVSS 9.8EG 9.82016-10-03
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
- CVE-2016-6199CRITICALCVSS 9.8EG 9.82017-02-07
ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.
- CVE-2016-6330CRITICALCVSS 9.8EG 9.82016-09-27
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserial…
- CVE-2016-6620CRITICALCVSS 9.8EG 9.82016-12-11
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object inst…
- CVE-2016-6793CRITICALCVSS 9.1EG 9.12017-07-17
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if runnin…
- CVE-2016-6809CRITICALCVSS 9.8EG 9.82017-04-06
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
- CVE-2016-6814CRITICALCVSS 9.8EG 9.82018-01-18
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was…
- CVE-2016-7050CRITICALCVSS 9.8EG 9.82017-06-08
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
- CVE-2016-7065HIGHCVSS 8.8EG 8.82016-10-13
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.
- CVE-2016-7124CRITICALCVSS 9.8EG 9.82016-09-12
ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data…
- CVE-2016-8511CRITICALCVSS 9.8EG 9.82018-02-15
A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was found.
- CVE-2016-8519CRITICALCVSS 9.8EG 9.82018-02-15
A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →