Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Telepresence System Software HIGH 10.0
CVE-2011-0372

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands…

Mitigation only
Fix from $1,950 2011-02-25
Openview Network Node Manager HIGH 10.0
CVE-2011-0271EPSS 7%

The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote att…

Mitigation only
Fix from $1,950 2011-01-13
Pandora Fms HIGH 9.0
CVE-2010-4278EPSS 11%

operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters…

Fix: after 3.1
Fix from $1,950 2010-12-02
Unified Communications Manager MEDIUM 6.8
CVE-2010-3039EPSS 9%

/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated…

No fix yet
Fix from $1,600 2010-11-09
Openswan MEDIUM 6.5
CVE-2010-3753

programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell m…

Patch available
Fix from $1,600 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3754

The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3757

Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 throug…

Mitigation only
Fix from $1,950 2010-10-05
Openswan MEDIUM 6.5
CVE-2010-3752

programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell m…

Patch available
Fix from $1,600 2010-10-05
Freeciv HIGH 10.0
CVE-2010-2445

freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua…

Patch available
Fix from $1,950 2010-07-08
Windows 2003 Server HIGH 9.3
CVE-2010-1885EPSS 75%

The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle…

No fix yet
Fix from $1,950 2010-06-15
Spamassassin Milter Plugin HIGH 9.3
CVE-2010-1132EPSS 9%

The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute…

No fix yet
Fix from $1,950 2010-03-27
Chumby One HIGH 10.0
CVE-2010-0418

The web interface in chumby one before 1.0.4 and chumby classic before 1.7.2 allows remote attackers to execute arbitrary commands via shell metachar…

Fix: after 1.7.1
Fix from $1,950 2010-03-10
Perforce Server HIGH 7.1
CVE-2010-0934

The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-system co…

No fix yet
Fix from $1,950 2010-03-05
Secure File Transfer Appliance HIGH 9.0
CVE-2009-4644

Accellion Secure File Transfer Appliance before 8_0_105 allows remote authenticated administrators to bypass the restricted shell and execute arbitra…

No fix yet
Fix from $1,950 2010-02-19
Zabbix MEDIUM 6.8
CVE-2009-4498EPSS 32%

The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.

Fix: after 1.7.4
Fix from $1,600 2009-12-31
Pear HIGH 10.0
CVE-2009-4025EPSS 6%

Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote atta…

Fix: after 0.21.1
Fix from $1,950 2009-11-29
Changetrack HIGH 7.2
CVE-2009-3233

changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is che…

Patch available
Fix from $1,950 2009-09-17
Footprints HIGH 10.0
CVE-2008-7158

Numara FootPrints 7.5a through 7.5a1 and 8.0 through 8.0a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) t…

Patch available
Fix from $1,950 2009-09-02
Ariadne Cms HIGH 9.0
CVE-2008-7125

pphoto in Ariadne before 2.6 allows remote authenticated users with certain privileges to execute arbitrary shell commands via vectors related to PIN…

Fix: after 2.4.1
Fix from $1,950 2009-08-31
Nagios HIGH 7.5
CVE-2009-2288EPSS 83%

statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute…

Fix: after 3.1.0
Fix from $1,950 2009-07-01
Dx Studio Player HIGH 9.3
CVE-2009-2011EPSS 40%

Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not …

Fix: after 3.0.29.0
Fix from $1,950 2009-06-16
Enhanced Picture Uploader Activex Control HIGH 9.3
CVE-2008-2475

eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the Pictur…

Fix: after 1.0.26
Fix from $1,950 2009-06-09
Dns Tools HIGH 10.0
CVE-2009-1916EPSS 10%

dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.

No fix yet
Fix from $1,950 2009-06-04
S3dplayer Standalone HIGH 9.3
CVE-2009-1792

The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6…

Mitigation only
Fix from $1,950 2009-05-29
Nweb2fax HIGH 7.5
CVE-2008-6669

viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in …

Fix: after 0.2.7
Fix from $1,950 2009-04-08
Adsl2\/2\+4 Port Router HIGH 10.0
CVE-2008-6554

cgi-bin/script in Aztech ADSL2/2+ 4-port router 3.7.0 build 070426 allows remote attackers to execute arbitrary commands via shell metacharacters in …

No fix yet
Fix from $1,950 2009-03-30
Dash MEDIUM 6.9
CVE-2009-0854

Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profi…

Mitigation only
Fix from $1,600 2009-03-11
Vim HIGH 9.3
CVE-2008-6235

The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename u…

Patch available
Fix from $1,950 2009-02-21
Tar.vim HIGH 9.3
CVE-2008-3074

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation…

Patch available
Fix from $1,950 2009-02-21
Vim HIGH 9.3
CVE-2008-3076EPSS 9%

The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used …

Patch available
Fix from $1,950 2009-02-21