Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,619 CVEs tagged with CWE-77952 Critical, 1,469 High, 772 Medium, 424 Low, 2 Unrated.

CVE-2016-10108

Published Jan 3, 2017

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-10107

Published Jan 3, 2017

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-10074

Published Dec 30, 2016

The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently exec…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-10034

Published Dec 30, 2016

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote at…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-6656

Published Dec 16, 2016

An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary commands can be injected into…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6609

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9835

Published Dec 5, 2016

Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by u…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-8969

Published Nov 3, 2016

git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as argum…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-8968

Published Nov 3, 2016

git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0920

Published Sep 21, 2016

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3081

Published Apr 26, 2016

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method:…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2002

Published Apr 20, 2016

The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-2056

Published Apr 13, 2016

xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 3,526-3,550 of 3,619 CVEsPage 142 of 145