Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-06-05 CVE-2018-1000193 Injection vulnerability in multiple products
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.
network
low complexity
jenkins oracle CWE-74
4.3
2018-06-04 CVE-2017-16043 Injection vulnerability in Shout Project Shout
Shout is an IRC client.
network
low complexity
shout-project CWE-74
6.1
2018-05-11 CVE-2017-6015 Injection vulnerability in Rockwellautomation Factorytalk Activation 4.00.02
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable.
local
low complexity
rockwellautomation CWE-74
7.8
2018-05-10 CVE-2017-18266 Injection vulnerability in multiple products
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
network
low complexity
freedesktop debian canonical CWE-74
8.8
2018-04-18 CVE-2016-10498 Injection vulnerability in Qualcomm products
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SDM630, SDM636, SDM660, and Snapdragon_High_Med_2016, stopping of the DTR prematurely causes micro kernel to be stuck.
network
low complexity
qualcomm CWE-74
critical
9.8
2018-04-17 CVE-2014-2294 Injection vulnerability in Openwebanalytics Open web Analytics
Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php.
network
low complexity
openwebanalytics CWE-74
critical
9.8
2018-04-13 CVE-2017-0372 Injection vulnerability in multiple products
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
network
low complexity
mediawiki debian CWE-74
critical
9.8
2018-04-11 CVE-2018-1273 Injection vulnerability in multiple products
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements.
network
low complexity
pivotal-software apache oracle CWE-74
critical
9.8
2018-04-03 CVE-2017-4028 Injection vulnerability in Mcafee products
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.
local
low complexity
mcafee CWE-74
4.4
2018-04-03 CVE-2015-1975 Injection vulnerability in IBM Tivoli Directory Server
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors related to argument injection.
local
low complexity
ibm CWE-74
7.8