Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Git HIGH 7.5
CVE-2008-5516

The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_se…

Mitigation only
Fix from $1,950 2009-01-20
Netatalk HIGH 9.3
CVE-2008-5718

The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute…

Fix: after 2.0.3
Fix from $1,950 2008-12-26
Phpcollab HIGH 10.0
CVE-2008-4304

general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified inpu…

Fix: after 2.5
Fix from $1,950 2008-12-23
Yast2 Backup HIGH 7.2
CVE-2008-4636

yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by…

Fix: after 2.16.6
Fix from $1,950 2008-11-27
Debian Linux HIGH 10.0
CVE-2008-4796EPSS 9%

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamat…

Fix: 2.6.3 / 4.2.2+
Fix from $1,950 2008-10-30
Fedora MEDIUM 6.8
CVE-2008-2575

cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RA…

Fix: 0.9.17+
Fix from $1,600 2008-06-06
Visual Foxpro HIGH 7.5
CVE-2007-5322EPSS 19%

Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary…

No fix yet
Fix from $1,950 2007-10-09
Visual Studio MEDIUM 6.8
CVE-2007-4891EPSS 31%

A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3…

No fix yet
Fix from $1,600 2007-09-14
Clamav HIGH 7.6
CVE-2007-4560EPSS 84%

clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters th…

Fix: after 0.91.1
Fix from $1,950 2007-08-28
Firefox MEDIUM 6.8
CVE-2007-4041EPSS 20%

Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL b…

Mitigation only
Fix from $1,600 2007-07-27
Workcentre HIGH 7.5
CVE-2006-6427

The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows r…

Patch available
Fix from $1,950 2006-12-10
Etomite HIGH 7.5
CVE-2006-0325

Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a …

Fix: after 0.6
Fix from $1,950 2006-01-20
Vim HIGH 9.3
CVE-2005-2368

vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the…

Patch available
Fix from $1,950 2005-07-26
Linux HIGH 10.0
CVE-2003-0041

Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.

Patch available
Fix from $1,950 2003-02-19
Vbulletin HIGH 7.5
CVE-2002-1660EPSS 11%

calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.

Fix: after 2.1.9
Fix from $1,950 2002-12-31
Terminal HIGH 7.2
CVE-2002-1898

Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is exec…

Fix: 1.3.1+
Fix from $1,950 2002-12-31
HTTP Server HIGH 7.5
CVE-2002-0061EPSS 50%

Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pip…

Fix: 1.3.24 / 2.0.34+
Fix from $1,950 2002-03-21
Sunos HIGH 10.0
CVE-2001-1583EPSS 83%

lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that…

Fix: after 5.9
Fix from $1,950 2001-12-31
Linux CRITICAL 9.8
CVE-1999-0043EPSS 45%

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

Mitigation only
Fix from $2,300 1996-12-04
HTTP Server HIGH 10.0
CVE-1999-0067EPSS 87%

phf CGI program allows remote command execution through shell metacharacters.

Mitigation only
Fix from $1,950 1996-03-20