Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,713 CVEs tagged with CWE-77968 Critical, 1,509 High, 784 Medium, 450 Low, 2 Unrated.

CVE-2013-7416

Published Dec 3, 2014

canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8517

Published Nov 17, 2014

The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2014-3524

Published Aug 26, 2014

Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-4336

Published Jun 22, 2014

The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metachar…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0773

Published Apr 12, 2014

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “CreateProcess.” This method contains validation to ensure an attacker cannot run arbitrary command lines. After vali…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4086

Published Sep 25, 2013

A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSC…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1823

Published May 11, 2012

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)…

CVSS 9.8 · Critical
evidence mentions
18
Buzz score
75.4
KEV listedPublic PoC observed

CVE-2007-3010

Published Sep 18, 2007

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metac…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2005-2773

Published Sep 2, 2005

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl,…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2005-2793

Published Sep 2, 2005

PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 3,701-3,713 of 3,713 CVEsPage 149 of 149