CWE-94
6,455 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (6,455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via t...Show more |
PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter. |
1Microsoft 2Windows Server 2008 Windows VistaApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is de...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is de...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "H...Show more |
1Microsoft 26.net Framework Excel ViewerExpression Web+23 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corrupt...Show more |
1Microsoft 7Windows 2000 Windows Media Format RuntimeWindows Media Player+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio f...Show more |
1Microsoft 26.net Framework Excel ViewerExpression Web+23 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word V...Show more |
1Microsoft 7.net Framework Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Head...Show more |
1Microsoft 7Windows 2000 Windows Media Format RuntimeWindows Media Player+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows...Show more |
1Microsoft 7.net Framework Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser...Show more |
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOT...Show more |
PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the DataDirectory parameter. |
Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL...Show more |
Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) sites/test/pages/conta...Show more |
Multiple PHP remote file inclusion vulnerabilities in Loggix Project 9.4.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathToIndex parameter to (1) Calendar.php, (2) Comment.php, (3)...Show more |
Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension 1.0.5 for Firefox allows remote authenticated SFTP users to cause victi...Show more |
PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code via a URL in the fm_includes_special parameter. |