Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,180 CVEs tagged with CWE-781,976 Critical, 3,126 High, 890 Medium, 188 Low, 0 Unrated.

CVE-2011-0373

Published Feb 25, 2011

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed req…

CVSS 9.0 · Critical

CVE-2011-0372

Published Feb 25, 2011

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, rela…

CVSS 10.0 · Critical

CVE-2011-0271

Published Jan 13, 2011

The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary co…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4278

Published Dec 2, 2010

operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3039

Published Nov 9, 2010

/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arb…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3757

Published Oct 5, 2010

Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3754

Published Oct 5, 2010

The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 uses val…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3753

Published Oct 5, 2010

programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the cisco_ban…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3752

Published Oct 5, 2010

programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) cisco_dns…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2445

Published Jul 8, 2010

freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1423

Published Apr 15, 2010

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows a…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2010-1132

Published Mar 27, 2010

The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0418

Published Mar 10, 2010

The web interface in chumby one before 1.0.4 and chumby classic before 1.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0934

Published Mar 5, 2010

The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-system commands by using a "p4 client"…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4644

Published Feb 19, 2010

Accellion Secure File Transfer Appliance before 8_0_105 allows remote authenticated administrators to bypass the restricted shell and execute arbitrary commands via shell metachar…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4498

Published Dec 31, 2009

The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4025

Published Nov 29, 2009

Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary she…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3233

Published Sep 17, 2009

changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7158

Published Sep 2, 2009

Numara FootPrints 7.5a through 7.5a1 and 8.0 through 8.0a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) transcriptFile parameter to MRc…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-7125

Published Aug 31, 2009

pphoto in Ariadne before 2.6 allows remote authenticated users with certain privileges to execute arbitrary shell commands via vectors related to PINP programs and the annotate co…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2288

Published Jul 1, 2009

statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-2011

Published Jun 16, 2009

Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.e…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1916

Published Jun 4, 2009

dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 6,126-6,150 of 6,180 CVEsPage 246 of 248