Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,188 CVEs tagged with CWE-781,979 Critical, 3,128 High, 890 Medium, 191 Low, 0 Unrated.

CVE-2017-11322

Published Oct 3, 2017

The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metacharacter in the argument to c…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11321

Published Oct 3, 2017

The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metacharacters in the less command.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14867

Published Sep 29, 2017

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, wh…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14001

Published Sep 26, 2017

An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injection vulnerability has been id…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11395

Published Sep 22, 2017

Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3431

Published Sep 19, 2017

Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14500

Published Sep 17, 2017

Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform us…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14429

Published Sep 13, 2017

The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code ex…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14405

Published Sep 13, 2017

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6796

Published Sep 7, 2017

A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to inject…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14135

Published Sep 4, 2017

enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrary OS commands via shell metac…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14127

Published Sep 4, 2017

Command Injection in the Ping Module in the Web Interface on Technicolor TD5336 OI_Fw_v7 devices allows remote attackers to execute arbitrary OS commands as root via shell metacha…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-14119

Published Sep 3, 2017

In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\snmpwalk.php does not properly restrict popen calls, which allows remote attackers to execute arbitrar…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14118

Published Sep 3, 2017

In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\interface.php does not properly restrict exec calls, which allows remote attackers to execute arbitrar…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14100

Published Sep 2, 2017

In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-10951

Published Aug 29, 2017

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerab…

CVSS 8.8 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2016-0634

Published Aug 28, 2017

The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11366

Published Aug 21, 2017

components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demons…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,851-5,875 of 6,188 CVEsPage 235 of 248