CWE-94
6,455 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (6,455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Autodesk 2Alias Wavefront Maya Autodesk MayaApr 23, 2026 Nov 24, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command o...Show more |
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application cal...Show more |
1Autodesk 2Autodesk Softimage Autodesk Softimage XsiApr 23, 2026 Nov 24, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demon...Show more |
Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, a...Show more |
1Microsoft 5Compatibility Pack Word Excel Powerpoint ExcelExcel Viewer+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibili...Show more |
1Microsoft 5Compatibility Pack Word Excel Powerpoint ExcelExcel Viewer+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers mem...Show more |
1Microsoft 5Compatibility Pack Word Excel Powerpoint ExcelExcel Viewer+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibili...Show more |
1Microsoft 5Compatibility Pack Word Excel Powerpoint ExcelExcel Viewer+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibili...Show more |
1Microsoft 5Compatibility Pack Word Excel Powerpoint ExcelExcel Viewer+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed re...Show more |
1Microsoft 5Compatibility Pack Word Excel Powerpoint ExcelExcel Viewer+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attack...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2008+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbi...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 23, 2026 Nov 11, 2009 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via...Show more |
Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA. |
The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug...Show more |
Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3464....Show more |
Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3465....Show more |
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arb...Show more |
PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parame...Show more |
PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path...Show more |
Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php...Show more |