Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-08-02 CVE-2014-8903 Command Injection vulnerability in IBM Curam Social Program Management
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.
network
low complexity
ibm CWE-77
8.8
2017-07-21 CVE-2017-9980 Command Injection vulnerability in Greenpacket Dx-350 Firmware 2.8.9.5G1.4.8Atheeb
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter.
network
low complexity
greenpacket CWE-77
critical
9.8
2017-07-19 CVE-2017-7977 Command Injection vulnerability in Unicon-Software Elux
The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and execute arbitrary commands with root privileges by inserting commands in a local configuration dialog in the control panel.
network
low complexity
unicon-software CWE-77
critical
9.8
2017-07-17 CVE-2017-2349 Command Injection vulnerability in Juniper Junos
A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allows a user with login access to the device to execute shell commands and elevate privileges.
network
low complexity
juniper CWE-77
8.8
2017-07-12 CVE-2017-4054 Command Injection vulnerability in Mcafee Advanced Threat Defense
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-77
8.8
2017-06-19 CVE-2017-4984 Command Injection vulnerability in EMC Vnx1 Firmware and Vnx2 Firmware
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection.
network
low complexity
emc CWE-77
critical
9.8
2017-06-13 CVE-2016-6655 Command Injection vulnerability in Cloudfoundry Cf-Mysql-Release
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31.
network
low complexity
cloudfoundry CWE-77
critical
9.8
2017-06-08 CVE-2017-4918 Command Injection vulnerability in VMWare Horizon View
VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script.
network
low complexity
vmware CWE-77
critical
9.8
2017-05-28 CVE-2015-9059 Command Injection vulnerability in Picocom Project Picocom
picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely.
network
low complexity
picocom-project CWE-77
critical
9.8
2017-05-23 CVE-2015-4046 Command Injection vulnerability in Alienvault Open Source Security Information Management
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.
network
low complexity
alienvault CWE-77
7.2