Vulnerabilities > Argument Injection or Modification

DATE CVE VULNERABILITY TITLE RISK
2020-08-31 CVE-2020-4492 Argument Injection or Modification vulnerability in IBM Spectrum Scale
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments.
local
low complexity
ibm CWE-88
2.1
2020-08-14 CVE-2020-15692 Argument Injection or Modification vulnerability in Nim-Lang NIM 1.2/1.2.2/1.2.4
In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser.
network
low complexity
nim-lang CWE-88
critical
10.0
2020-08-11 CVE-2020-17367 Argument Injection or Modification vulnerability in multiple products
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
7.8
2020-07-16 CVE-2020-3380 Argument Injection or Modification vulnerability in Cisco Data Center Network Manager
A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system.
local
low complexity
cisco CWE-88
7.2
2020-06-18 CVE-2020-14421 Argument Injection or Modification vulnerability in Aapanel
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen.
network
low complexity
aapanel CWE-88
7.2
2020-06-16 CVE-2020-7496 Argument Injection or Modification vulnerability in SE Ecostruxure Operator Terminal Expert 3.1
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.
network
se CWE-88
6.8
2020-05-21 CVE-2020-7808 Argument Injection or Modification vulnerability in Raonwiz Raon K Upload 2018.0.2.51
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.
network
low complexity
raonwiz CWE-88
critical
9.8
2020-03-16 CVE-2020-1738 Argument Injection or Modification vulnerability in Redhat products
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified.
local
high complexity
redhat CWE-88
3.9
2020-03-16 CVE-2020-5546 Argument Injection or Modification vulnerability in Mitsubishielectric Iu1-1M20-D Firmware
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop the network functions or execute malware via a specially crafted packet.
low complexity
mitsubishielectric CWE-88
5.8
2020-03-02 CVE-2020-6799 Argument Injection or Modification vulnerability in Mozilla Firefox
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types.
network
high complexity
mozilla CWE-88
5.1