Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-02-03 CVE-2018-1184 OS Command Injection vulnerability in Dell products
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3.
local
low complexity
dell CWE-78
6.7
2018-01-29 CVE-2018-6388 OS Command Injection vulnerability in Iball Ib-Wra150N Firmware 1.2.6
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the Diagnostics page.
network
low complexity
iball CWE-78
8.8
2018-01-27 CVE-2018-6353 OS Command Injection vulnerability in Electrum
The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended workstation, which makes it easier for attackers to steal Bitcoin via hook code that runs at a later time when the wallet password has been entered, a different vulnerability than CVE-2018-1000022.
local
low complexity
electrum CWE-78
7.8
2018-01-26 CVE-2018-0506 OS Command Injection vulnerability in Nootka Project Nootka 1.0.1/1.2.7/1.4.4
Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
network
low complexity
nootka-project CWE-78
critical
9.8
2018-01-26 CVE-2017-1000393 OS Command Injection vulnerability in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'Launch agent via execution of command on master'.
network
low complexity
jenkins CWE-78
8.8
2018-01-24 CVE-2018-1000006 OS Command Injection vulnerability in Atom Electron 0.33.4/1.8.2
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL.
network
low complexity
atom CWE-78
8.8
2018-01-24 CVE-2017-1000502 OS Command Injection vulnerability in Jenkins EC2
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched.
network
low complexity
jenkins CWE-78
8.8
2018-01-22 CVE-2016-10709 OS Command Injection vulnerability in Pfsense 2.2.6
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.
network
low complexity
pfsense CWE-78
8.8
2018-01-19 CVE-2017-18044 OS Command Injection vulnerability in Commvault 11.0
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6.
network
low complexity
commvault CWE-78
critical
9.8
2018-01-18 CVE-2018-0115 OS Command Injection vulnerability in Cisco Staros
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected host operating system.
local
low complexity
cisco CWE-78
6.7