Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,377 CVEs tagged with CWE-782,056 Critical, 3,220 High, 906 Medium, 194 Low, 1 Unrated.

CVE-2014-1982

Published Mar 31, 2014

The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers…

CVSS 10.0 · Critical

CVE-2014-0887

Published Mar 25, 2014

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspeci…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0886

Published Mar 25, 2014

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary c…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6719

Published Mar 6, 2014

delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to e…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3365

Published Feb 4, 2014

TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to internet/ipv6.asp; (2) remote…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5946

Published Dec 19, 2013

The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B4…

CVSS 10.0 · Critical

CVE-2013-7104

Published Dec 14, 2013

McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML elem…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-7103

Published Dec 14, 2013

McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in a (1) TestFile XML element or…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-4457

Published Nov 2, 2013

The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5530

Published Oct 25, 2013

The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 be…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4108

Published Oct 13, 2013

The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary operating-system commands via crafted paramet…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4075

Published Oct 5, 2013

Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in unspecified command parameters, aka Bug IDs CSCtf19827 and CSCtf27788.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5486

Published Sep 23, 2013

Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbit…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-4984

Published Sep 10, 2013

The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metachar…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6605

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unsp…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 6,251-6,275 of 6,377 CVEsPage 251 of 256