Vulnerability index

Browse CVEs

18 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Debian Linux MEDIUM 6.5
CVE-2024-25082

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

Fix: after 20230101
Fix from $1,600 2024-02-26
Debian Linux HIGH 7.8
CVE-2022-42906

powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration…

Fix: 1.3.2+
Fix from $1,950 2022-10-13
Debian Linux HIGH 8.8
CVE-2022-3008

The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T…

Fix: 2.6.0+
Fix from $1,950 2022-09-05
Debian Linux HIGH 8.8
CVE-2019-9972

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the …

No fix yet
Fix from $1,950 2022-06-07
Debian Linux CRITICAL 9.8
CVE-2021-43113EPSS 5%

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghost…

Fix: 7.1.17+
Fix from $2,300 2021-12-15
Debian Linux CRITICAL 9.8
CVE-2021-38173

Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorize…

Fix: 0.31.2+
Fix from $2,300 2021-08-07
Debian Linux HIGH 8.8
CVE-2015-1877

The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which all…

Patch available
Fix from $1,950 2021-06-02
Debian Linux HIGH 7.8
CVE-2019-14868

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypas…

Fix: 10.15.5+
Fix from $1,950 2020-04-02
Debian Linux MEDIUM 6.5
CVE-2019-12921EPSS 8%

In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of Translate…

Fix: 1.3.32+
Fix from $1,600 2020-03-18
Debian Linux CRITICAL 9.8
CVE-2019-17361EPSS 15%

In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticat…

Fix: after 2019.2.0
Fix from $2,300 2020-01-17
Debian Linux CRITICAL 9.8
CVE-2019-1010174

CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attac…

Fix: 2.3.4+
Fix from $2,300 2019-07-25
Debian Linux HIGH 7.8
CVE-2019-1000018

rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp p…

No fix yet
Fix from $1,950 2019-02-04
Debian Linux HIGH 7.8
CVE-2015-8971

Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the…

Patch available
Fix from $1,950 2017-01-23
Debian Linux CRITICAL 9.8
CVE-2015-0857EPSS 5%

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within…

Mitigation only
Fix from $2,300 2016-05-06
Debian Linux HIGH 8.8
CVE-2016-2056EPSS 55%

xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the …

Patch available
Fix from $1,950 2016-04-13
Mime Support HIGH 7.5
CVE-2014-7209

run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metach…

Fix: after 3.52-1
Fix from $1,950 2015-01-06
Debian Linux HIGH 7.5
CVE-2014-8990EPSS 5%

default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.

Fix: after 2.1.5
Fix from $1,950 2014-12-05
Debian Linux HIGH 7.8
CVE-2010-4345 KEVEPSS 18%

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration …

Fix: after 4.72
Fix from $1,950 2010-12-14