Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-02-13 CVE-2019-8318 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
critical
9.0
2019-02-13 CVE-2019-8317 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
critical
9.0
2019-02-13 CVE-2019-8316 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
critical
9.0
2019-02-13 CVE-2019-8315 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
critical
9.0
2019-02-13 CVE-2019-8314 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
critical
9.0
2019-02-13 CVE-2019-8313 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
critical
9.0
2019-02-13 CVE-2019-8312 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
critical
9.0
2019-02-11 CVE-2019-5736 OS Command Injection vulnerability in multiple products
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec.
8.6
2019-02-08 CVE-2019-7632 OS Command Injection vulnerability in Lifesize products
LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in the support/mtusize.php mtu_size parameter.
network
low complexity
lifesize CWE-78
critical
9.0
2019-02-07 CVE-2019-3704 OS Command Injection vulnerability in Dell EMC Vnx2 Firmware
VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability.
local
low complexity
dell CWE-78
7.2