Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-09-01 CVE-2017-3897 Code Injection vulnerability in Mcafee Livesafe and Security Scan Plus
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.
network
low complexity
mcafee CWE-94
critical
9.8
2017-08-31 CVE-2017-0899 Code Injection vulnerability in multiple products
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
network
low complexity
rubygems debian redhat CWE-94
critical
9.8
2017-08-30 CVE-2017-1440 Code Injection vulnerability in IBM Emptoris Services Procurement
IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files.
network
low complexity
ibm CWE-94
8.8
2017-08-29 CVE-2017-10844 Code Injection vulnerability in Basercms
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.
network
low complexity
basercms CWE-94
8.8
2017-08-29 CVE-2017-10835 Code Injection vulnerability in Nippon-Antenna Scr02Hd Firmware 1.0.3.1000
"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vectors.
network
low complexity
nippon-antenna CWE-94
8.8
2017-08-29 CVE-2014-8872 Code Injection vulnerability in AVM products
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
local
low complexity
avm CWE-94
7.8
2017-08-17 CVE-2017-6782 Code Injection vulnerability in Cisco Prime Infrastructure 3.2(0.0)
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application.
network
low complexity
cisco CWE-94
5.4
2017-08-17 CVE-2011-0469 Code Injection vulnerability in Suse Opensuse
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
network
low complexity
suse CWE-94
critical
9.8
2017-08-14 CVE-2017-1469 Code Injection vulnerability in IBM Infosphere Information Server 11.3/11.5/9.1
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories.
local
low complexity
ibm CWE-94
7.8
2017-08-10 CVE-2017-3753 Code Injection vulnerability in Lenovo products
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc.
low complexity
lenovo CWE-94
6.8