Vulnerability index

Browse CVEs

3,672 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Mac Os X HIGH 7.5
CVE-2014-8517EPSS 69%

The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.…

Patch available
Fix from $1,950 2014-11-17
Openoffice HIGH 9.3
CVE-2014-3524EPSS 15%

Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp…

Fix: 4.1.1 / 4.2.6+
Fix from $1,950 2014-08-26
Cups Filters MEDIUM 5.8
CVE-2014-4336

The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitra…

Fix: after 1.0.52
Fix from $1,600 2014-06-22
Advantech Webaccess HIGH 7.5
CVE-2014-0773

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “CreateProcess.” This method contains validation to ensure an attacker cannot run arbit…

Fix: after 7.1
Fix from $1,950 2014-04-12
Unified Computing System MEDIUM 5.1
CVE-2012-4086

A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via inva…

Mitigation only
Fix from $1,600 2013-09-25
PHP CRITICAL 9.8
CVE-2012-1823 KEVEPSS 100%

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query string…

Fix: 5.3.12 / 5.4.2+
Fix from $2,300 2012-05-11
Debian Linux HIGH 7.8
CVE-2010-4345 KEVEPSS 18%

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration …

Fix: after 4.72
Fix from $1,950 2010-12-14
Openoffice HIGH 9.3
CVE-2010-0136EPSS 8%

OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remo…

Mitigation only
Fix from $1,950 2010-02-16
Omnipcx Enterprise Communication Server CRITICAL 9.8
CVE-2007-3010 KEVEPSS 97%

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbi…

Fix: after 7.1
Fix from $2,300 2007-09-18
Openview Network Node Manager CRITICAL 9.8
CVE-2005-2773 KEVEPSS 74%

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node para…

Fix: after 7.50
Fix from $2,300 2005-09-02
Phpldapadmin HIGH 7.5
CVE-2005-2793

PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the …

No fix yet
Fix from $1,950 2005-09-02
Irix HIGH 7.3
CVE-1999-0039EPSS 16%

webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.

Mitigation only
Fix from $1,950 1997-05-06