Total
3411 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-0143 | 1 Qnap | 3 Nas, Surveillance Station Pro, Viostor Network Video Recorder | 2013-06-10 | 6.5 MEDIUM | N/A |
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string. | |||||
CVE-2012-4707 | 1 3s-software | 1 Codesys Gateway-server | 2013-05-21 | 10.0 HIGH | N/A |
3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access. | |||||
CVE-2013-3508 | 1 Gwos | 1 Groundwork Monitor | 2013-05-08 | 6.5 MEDIUM | N/A |
html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via vectors involving file editing. | |||||
CVE-2013-3079 | 1 Vmware | 1 Vcenter Server Appliance | 2013-05-01 | 9.0 HIGH | N/A |
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access. | |||||
CVE-2013-0132 | 1 Parallels | 1 Parallels Plesk Panel | 2013-04-19 | 6.8 MEDIUM | N/A |
The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables. | |||||
CVE-2012-2290 | 1 Emc | 1 Networker Module For Microsoft Applications | 2013-04-19 | 9.3 HIGH | N/A |
The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel. | |||||
CVE-2012-2085 | 1 Gajim | 1 Gajim | 2013-04-19 | 6.8 MEDIUM | N/A |
The exec_command function in common/helpers.py in Gajim before 0.15 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an href attribute. | |||||
CVE-2013-1898 | 1 Digineo | 1 Thumbshooter | 2013-04-10 | 7.5 HIGH | N/A |
lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |||||
CVE-2013-1875 | 1 Rubygems | 1 Command Wrap | 2013-03-21 | 7.5 HIGH | N/A |
command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename. | |||||
CVE-2013-2615 | 1 Rubygems | 1 Fastreader | 2013-03-21 | 7.5 HIGH | N/A |
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |||||
CVE-2013-1638 | 1 Opera | 1 Opera Browser | 2013-03-08 | 9.3 HIGH | N/A |
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document. | |||||
CVE-2013-1637 | 1 Opera | 1 Opera Browser | 2013-03-08 | 9.3 HIGH | N/A |
Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events. | |||||
CVE-2012-4017 | 2 Google, Jb\+ | 2 Android, Jigbrowser\+ | 2013-03-02 | 4.3 MEDIUM | N/A |
The jigbrowser+ application before 1.5.0 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. | |||||
CVE-2012-0439 | 1 Novell | 1 Groupwise | 2013-02-25 | 9.3 HIGH | N/A |
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method. | |||||
CVE-2013-0108 | 1 Honeywell | 3 Comfortpoint Open Manager Station, Enterprise Buildings Integrator, Symmetre | 2013-02-25 | 6.8 MEDIUM | N/A |
An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages allows remote attackers to execute arbitrary code via a crafted HTML document. | |||||
CVE-2011-0554 | 1 Symantec | 1 Im Manager | 2013-02-07 | 7.5 HIGH | N/A |
The management console in Symantec IM Manager before 8.4.18 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "code injection issue." | |||||
CVE-2012-5159 | 1 Phpmyadmin | 1 Phpmyadmin | 2013-01-26 | 7.5 HIGH | N/A |
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack. | |||||
CVE-2012-0295 | 1 Symantec | 1 Endpoint Protection | 2013-01-04 | 9.3 HIGH | N/A |
The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294. | |||||
CVE-2012-6465 | 1 Opera | 1 Opera Browser | 2013-01-02 | 9.3 HIGH | N/A |
Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image. | |||||
CVE-2012-5690 | 1 Realnetworks | 2 Realplayer, Realplayer Sp | 2012-12-19 | 9.3 HIGH | N/A |
RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file that triggers access to an invalid pointer. |