Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,386 CVEs tagged with CWE-782,056 Critical, 3,225 High, 909 Medium, 195 Low, 1 Unrated.

CVE-2015-4718

Published Oct 21, 2015

The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6008

Published Sep 28, 2015

install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5690

Published Sep 20, 2015

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions a…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2980

Published Aug 8, 2015

The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitive information or execute OS co…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2979

Published Jul 29, 2015

Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4279

Published Jul 20, 2015

The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by lever…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4244

Published Jul 10, 2015

The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for st…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4224

Published Jun 26, 2015

Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug I…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4183

Published Jun 17, 2015

Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9727

Published May 29, 2015

AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2015-2845

Published May 12, 2015

The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATH_INFO.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-2844

Published May 12, 2015

The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0691

Published Apr 17, 2015

A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID C…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1388

Published Mar 24, 2015

The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attac…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0525

Published Mar 12, 2015

The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vec…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0977

Published Feb 27, 2015

Network Vision IntraVue before 2.3.0a14 on Windows allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-6041

Published Dec 27, 2014

index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,201-6,225 of 6,386 CVEsPage 249 of 256