• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-502

CVE-2021-32742

February 23, 2023 by

Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens up the potential for exposing server memory and/or crashing the server (Denial of Service) for applications where untrusted data can end up in said function. Vapor does not currently use this function itself so this only impact applications that use the impacted function directly or through other dependencies. The vulnerability is patched in version 4.47.2. As a workaround, one may use an alternative to Vapor’s built-in `Data.init(base32Encoded:)`.

CVE-2021-32634

February 23, 2023 by

Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the [`WorkSpaceClientEnqueue.action`](https://github.com/NationalSecurityAgency/emissary/blob/30c54ef16c6eb6ed09604a929939fb9f66868382/src/main/java/emissary/server/mvc/internal/WorkSpaceClientEnqueueAction.java) REST endpoint. This issue may lead to post-auth Remote Code Execution. This issue has been patched in version 6.5.0. As a workaround, one can disable network access to Emissary from untrusted sources.

CVE-2021-32568

February 23, 2023 by

mrdoc is vulnerable to Deserialization of Untrusted Data

CVE-2021-32098

February 23, 2023 by

Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

CVE-2021-32075

February 23, 2023 by

Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.

CVE-2021-31819

February 23, 2023 by

In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 83
  • Go to page 84
  • Go to page 85
  • Go to page 86
  • Go to page 87
  • Interim pages omitted …
  • Go to page 129
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE