CWE-74
4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (4,976)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian MozillaRedhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jun 11, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vul...Show more |
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included...Show more |
1Apple 4Apple Tv Iphone OsMac Os X+1 moreNov 21, 2024 Jun 8, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" componen...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jun 5, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control ch...Show more |
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3. |
1Rockwellautomation 1Factorytalk Activation Nov 21, 2024 May 11, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable. This may al...Show more |
3Canonical DebianFreedesktop3Debian Linux Ubuntu LinuxXdg UtilsNov 21, 2024 May 10, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-...Show more |
1Qualcomm 30Mdm9206 Firmware Mdm9607 FirmwareMdm9615 Firmware+27 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/S...Show more |
1Openwebanalytics 1Open Web Analytics Nov 21, 2024 Apr 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities. |
1Mcafee 6Anti Virus Plus Endpoint SecurityHost Intrusion Prevention+3 moreNov 21, 2024 Apr 3, 2018 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulatio...Show more |
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before...Show more |
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assisted attackers to inject arbitrary commands...Show more |
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's bro...Show more |
1Trendmicro 1Email Encryption Gateway Jun 17, 2026 Mar 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems. |
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server. |
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnera...Show more |
1Samsung 2Knox Enterprise Mobility Management Knox Identity Access ManagementNov 21, 2024 Feb 20, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's...Show more |
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x). |
webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrate...Show more |