Skip to main content

CWE archive

CWE-116 CVEs

Programmatic archive

496 CVEs tagged with CWE-11665 Critical, 158 High, 229 Medium, 44 Low, 0 Unrated.

CVE-2018-16386

Published Jul 5, 2019

An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18838

Published Jun 18, 2019

An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter to api/v1/registry.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0857

Published Apr 9, 2019

A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8920

Published Dec 24, 2018

Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to hav…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8609

Published Nov 14, 2018

A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics serv…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-4267

Published Feb 19, 2018

The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2389

Published Feb 14, 2018

Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12340

Published Nov 30, 2017

A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allo…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12064

Published Aug 1, 2017

The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8303

Published May 5, 2017

An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-9938

Published Mar 20, 2017

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2568

Published Feb 13, 2017

pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3063

Published Feb 7, 2017

Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API call…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-496 of 496 CVEsPage 20 of 20