Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,179 CVEs tagged with CWE-781,976 Critical, 3,126 High, 890 Medium, 187 Low, 0 Unrated.

CVE-2012-4361

Published Aug 20, 2012

lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sec…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2986

Published Aug 20, 2012

lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) first,…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4177

Published Aug 7, 2012

The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2976

Published Jul 23, 2012

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2953

Published Jul 23, 2012

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3076

Published Jul 12, 2012

The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka B…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3075

Published Jul 12, 2012

The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed requ…

CVSS 9.0 · Critical

CVE-2012-2516

Published Jul 5, 2012

An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy H…

CVSS 9.3 · Critical

CVE-2012-3366

Published Jul 3, 2012

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to t…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1795

Published Mar 20, 2012

webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter, as exploited in the wild in March…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4002

Published Nov 30, 2011

HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4502

Published Nov 22, 2011

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with…

CVSS 10.0 · Critical

CVE-2011-1513

Published Nov 4, 2011

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to injec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2148

Published May 20, 2011

Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a leading and trailing & (ampersand)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0456

Published Mar 11, 2011

webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0381

Published Feb 25, 2011

Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0378

Published Feb 25, 2011

The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, relate…

CVSS 8.3 · High

CVE-2011-0375

Published Feb 25, 2011

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrary commands via a malformed req…

CVSS 9.0 · Critical

CVE-2011-0374

Published Feb 25, 2011

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed req…

CVSS 9.0 · Critical

CVE-2011-0373

Published Feb 25, 2011

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed req…

CVSS 9.0 · Critical
Showing 6,101-6,125 of 6,179 CVEsPage 245 of 248