Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,702 CVEs tagged with CWE-77968 Critical, 1,508 High, 779 Medium, 445 Low, 2 Unrated.

CVE-2014-7209

Published Jan 6, 2015

run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9277

Published Jan 4, 2015

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7418

Published Jan 2, 2015

cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell metacharacters in the TABLE parameter. NO…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3556

Published Dec 29, 2014

The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4663

Published Dec 28, 2014

git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9188

Published Dec 27, 2014

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a diffe…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-7208

Published Dec 19, 2014

GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-7285

Published Dec 17, 2014

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings int…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6260

Published Dec 15, 2014

Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary commands or cause a denial of s…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-8515

Published Dec 12, 2014

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2810

Published Dec 8, 2014

Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attac…

CVSS 10.0 · Critical

CVE-2014-9144

Published Dec 5, 2014

Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (setobject_ip parameter).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7416

Published Dec 3, 2014

canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8517

Published Nov 17, 2014

The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2014-3524

Published Aug 26, 2014

Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-4336

Published Jun 22, 2014

The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metachar…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0773

Published Apr 12, 2014

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “CreateProcess.” This method contains validation to ensure an attacker cannot run arbitrary command lines. After vali…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4086

Published Sep 25, 2013

A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSC…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1823

Published May 11, 2012

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)…

CVSS 9.8 · Critical
evidence mentions
18
Buzz score
75.4
KEV listedPublic PoC observed

CVE-2007-3010

Published Sep 18, 2007

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metac…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort
Showing 3,676-3,700 of 3,702 CVEsPage 148 of 149