Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,619 CVEs tagged with CWE-77952 Critical, 1,469 High, 772 Medium, 424 Low, 2 Unrated.

CVE-2015-5349

Published Apr 11, 2016

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0861

Published Feb 5, 2016

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7541

Published Jan 8, 2016

The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary cod…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5003

Published Jan 3, 2016

The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6613

Published Nov 3, 2015

Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted applicati…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7839

Published Oct 15, 2015

SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf inv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5082

Published Sep 28, 2015

Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpa…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6547

Published Sep 20, 2015

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot ti…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5274

Published Sep 18, 2015

rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6912

Published Sep 11, 2015

Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5474

Published Aug 13, 2015

BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1561

Published Jul 14, 2015

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5453

Published Jul 8, 2015

Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4525

Published Jul 4, 2015

The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3716

Published Jul 3, 2015

Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3678

Published Jul 3, 2015

AppleThunderboltEDMService in Apple OS X before 10.10.4 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified Thunderbolt commands.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1986

Published Jun 30, 2015

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than C…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,551-3,575 of 3,619 CVEsPage 143 of 145