Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,377 CVEs tagged with CWE-782,056 Critical, 3,220 High, 906 Medium, 194 Low, 1 Unrated.

CVE-2017-10904

Published Dec 16, 2017

Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17405

Published Dec 15, 2017

Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the loc…

CVSS 8.8 · High

CVE-2017-16921

Published Dec 8, 2017

In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can mani…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17458

Published Dec 7, 2017

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17055

Published Dec 7, 2017

Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id para…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1253

Published Dec 5, 2017

The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000159

Published Nov 27, 2017

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16934

Published Nov 24, 2017

The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16926

Published Nov 22, 2017

Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (providing a source tree for O…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000215

Published Nov 17, 2017

ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000203

Published Nov 17, 2017

ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000235

Published Nov 17, 2017

I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12305

Published Nov 16, 2017

A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection.…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12636

Published Nov 14, 2017

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequent…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-1453

Published Nov 13, 2017

IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16667

Published Nov 8, 2017

backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16641

Published Nov 7, 2017

lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 6,001-6,025 of 6,377 CVEsPage 241 of 256