Vulnerabilities > Improper Control of Dynamically-Managed Code Resources

DATE CVE VULNERABILITY TITLE RISK
2022-05-16 CVE-2021-23267 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Crafter CMS
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.
network
low complexity
craftercms CWE-913
8.8
2022-02-24 CVE-2022-25355 Improper Control of Dynamically-Managed Code Resources vulnerability in Ec-Cube
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.
network
low complexity
ec-cube CWE-913
5.3
2022-02-16 CVE-2022-25265 Improper Control of Dynamically-Managed Code Resources vulnerability in multiple products
In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20).
local
low complexity
linux netapp CWE-913
7.8
2021-12-20 CVE-2021-42809 Improper Control of Dynamically-Managed Code Resources vulnerability in Thalesgroup Sentinel Protection Installer 7.7.0
Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code.
local
low complexity
thalesgroup CWE-913
7.8
2021-12-02 CVE-2021-23258 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Crafter CMS
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans.
network
low complexity
craftercms CWE-913
7.2
2021-12-02 CVE-2021-23259 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Crafter CMS
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage.
network
low complexity
craftercms CWE-913
7.2
2021-12-02 CVE-2021-23262 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Crafter CMS
Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.
network
low complexity
craftercms CWE-913
7.2
2021-08-03 CVE-2021-32813 Improper Control of Dynamically-Managed Code Resources vulnerability in Traefik
Traefik is an HTTP reverse proxy and load balancer.
network
high complexity
traefik CWE-913
8.1
2021-08-02 CVE-2021-22387 Improper Control of Dynamically-Managed Code Resources vulnerability in Huawei Emui and Magic UI
There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to remotely execute commands.
network
low complexity
huawei CWE-913
critical
9.8
2021-05-11 CVE-2021-32563 Improper Control of Dynamically-Managed Code Resources vulnerability in Xfce Thunar
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.
network
low complexity
xfce CWE-913
critical
9.8