CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
6,865 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 35 of 138
- CVE-2013-1323HIGHCVSS v2 9.3EG 9.32013-05-15
Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
- CVE-2013-1335HIGHCVSS v2 9.3EG 9.32013-05-15
Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
- CVE-2013-1347CRITICALCVSS 8.8EG 9.0⚠ KEV2013-05-05
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May…
- CVE-2013-1349HIGHCVSS v2 7.5EG 7.52013-12-09
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.
- CVE-2013-1412HIGHCVSS v2 7.5EG 7.52014-06-02
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.
- CVE-2013-1435HIGHCVSS v2 7.5EG 7.52013-08-23
(1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
- CVE-2013-1436HIGHCVSS v2 7.5EG 7.52014-10-06
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated us…
- CVE-2013-1488HIGHCVSS v2 10.0EG 10.02013-03-08
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString call…
- CVE-2013-1491HIGHCVSS v2 10.0EG 10.02013-03-08
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via vectors related …
- CVE-2013-1637HIGHCVSS v2 9.3EG 9.32013-02-08
Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.
- CVE-2013-1638HIGHCVSS v2 9.3EG 9.32013-02-08
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
- CVE-2013-1647MEDIUMCVSS v2 5.0EG 5.02013-09-05
Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a craf…
- CVE-2013-1666CRITICALCVSS 9.8EG 9.82019-11-01
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
- CVE-2013-1688HIGHCVSS v2 9.3EG 9.32013-06-26
The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to execute arbitrary JavaScript code via a crafted web site.
- CVE-2013-1762MEDIUMCVSS v2 6.6EG 6.62013-03-08
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that trigger…
- CVE-2013-1850MEDIUMCVSS v2 6.5EG 6.52014-03-14
Multiple incomplete blacklist vulnerabilities in (1) import.php and (2) ajax/uploadimport.php in apps/contacts/ in ownCloud before 4.0.13 and 4.5.x before 4.5.8 allow remote authenticated users to execute arbitrary PHP code by uploading a …
- CVE-2013-1875HIGHCVSS v2 7.5EG 7.52013-03-20
command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename.
- CVE-2013-1898HIGHCVSS v2 7.5EG 7.52013-04-09
lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
- CVE-2013-1899MEDIUMCVSS v2 6.5EG 6.52013-04-04
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configur…
- CVE-2013-2121MEDIUMCVSS v2 6.0EG 6.02013-07-31
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
- CVE-2013-2208MEDIUMCVSS v2 6.8EG 6.82013-10-28
tpp 1.3.1 allows remote attackers to execute arbitrary commands via a --exec command in a TPP template file.
- CVE-2013-2267HIGHCVSS 7.2EG 7.22020-01-27
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.
- CVE-2013-2549HIGHCVSS v2 7.5EG 7.52013-03-11
Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox," as demonstrated by George Hotz during a Pwn2Own competition at CanSecWest 2013.
- CVE-2013-2582MEDIUMCVSS v2 5.0EG 5.02013-09-05
CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP headers and conduc…
- CVE-2013-2615HIGHCVSS v2 7.5EG 7.52013-03-20
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
- CVE-2013-2617HIGHCVSS v2 7.5EG 7.52013-03-20
lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
- CVE-2013-2751HIGHCVSS v2 10.0EG 10.02013-12-12
Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to execute arbitrary Perl code via a crafted request, re…
- CVE-2013-2802HIGHCVSS v2 10.0EG 10.02013-08-21
The universal protocol implementation in Sixnet UDR before 2.0 and RTU firmware before 4.8 allows remote attackers to execute arbitrary code; read, modify, or create files; or obtain file metadata via function opcodes.
- CVE-2013-2817HIGHCVSS v2 9.3EG 9.32014-02-24
An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary programs via a crafted HTML document in conjunction with a Login Client button click.
- CVE-2013-2827HIGHCVSS v2 7.5EG 7.52014-01-15
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the Projec…
- CVE-2013-2950LOWCVSS v2 3.5EG 3.52013-06-03
CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allow…
- CVE-2013-3079HIGHCVSS v2 9.0EG 9.02013-05-01
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access.
- CVE-2013-3127HIGHCVSS v2 9.3EG 9.32013-07-10
The Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime 11 and Windows Media Player 11 and 12 allows remote attackers to execute arbitrary code v…
- CVE-2013-3129HIGHCVSS 7.8EG 7.92013-07-10
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W…
- CVE-2013-3131HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via…
- CVE-2013-3132HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser appli…
- CVE-2013-3133HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (…
- CVE-2013-3134HIGHCVSS v2 9.3EG 9.32013-07-10
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET F…
- CVE-2013-3143HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerabil…
- CVE-2013-3144HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulner…
- CVE-2013-3145HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability tha…
- CVE-2013-3146HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability th…
- CVE-2013-3147HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
- CVE-2013-3148HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulner…
- CVE-2013-3149HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
- CVE-2013-3150HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability tha…
- CVE-2013-3151HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulner…
- CVE-2013-3152HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability th…
- CVE-2013-3153HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulner…
- CVE-2013-3161HIGHCVSS v2 9.3EG 9.32013-07-10
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerabil…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →