Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-02-13 CVE-2019-8319 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
8.8
2019-02-13 CVE-2019-8318 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
8.8
2019-02-13 CVE-2019-8317 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
8.8
2019-02-13 CVE-2019-8316 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
8.8
2019-02-13 CVE-2019-8315 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
8.8
2019-02-13 CVE-2019-8314 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
8.8
2019-02-13 CVE-2019-8313 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
8.8
2019-02-13 CVE-2019-8312 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.12A1
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1.
network
low complexity
dlink CWE-78
8.8
2019-02-11 CVE-2019-5736 OS Command Injection vulnerability in multiple products
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec.
8.6
2019-02-08 CVE-2019-7632 OS Command Injection vulnerability in Lifesize products
LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in the support/mtusize.php mtu_size parameter.
network
low complexity
lifesize CWE-78
8.8