Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-07-09 CVE-2018-4995 Injection vulnerability in Adobe Acrobat DC
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injection vulnerability.
network
low complexity
adobe CWE-74
critical
9.8
2018-06-21 CVE-2018-0313 Injection vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exploit.
network
low complexity
cisco CWE-74
8.8
2018-06-11 CVE-2017-7848 Injection vulnerability in multiple products
RSS fields can inject new lines into the created email structure, modifying the message body.
network
low complexity
mozilla redhat debian CWE-74
5.3
2018-06-11 CVE-2017-7846 Injection vulnerability in multiple products
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g.
network
low complexity
redhat debian mozilla CWE-74
8.8
2018-06-11 CVE-2017-7788 Injection vulnerability in Mozilla Firefox
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin".
network
low complexity
mozilla CWE-74
critical
9.8
2018-06-08 CVE-2018-4235 Injection vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-74
5.5
2018-06-05 CVE-2018-1000193 Injection vulnerability in multiple products
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.
network
low complexity
jenkins oracle CWE-74
4.3
2018-06-04 CVE-2017-16043 Injection vulnerability in Shout Project Shout
Shout is an IRC client.
network
low complexity
shout-project CWE-74
6.1
2018-05-11 CVE-2017-6015 Injection vulnerability in Rockwellautomation Factorytalk Activation 4.00.02
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable.
local
low complexity
rockwellautomation CWE-74
7.8
2018-05-10 CVE-2017-18266 Injection vulnerability in multiple products
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
network
low complexity
freedesktop debian canonical CWE-74
8.8