VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 106 of 350
  • CVE-2023-39469HigMay 3, 2024
    risk 0.51cvss 7.2epss 0.58

    PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2024-28699HigApr 22, 2024
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutputDev function.

  • CVE-2024-25376HigApr 11, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.

  • CVE-2024-30202HigMar 25, 2024
    risk 0.51cvss 7.8epss 0.01

    In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

  • CVE-2024-28116HigMar 21, 2024
    risk 0.51cvss 8.8epss 0.06

    Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbitrary code on the remote server…

  • CVE-2024-24520HigMar 21, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

  • CVE-2024-21892HigFeb 20, 2024
    risk 0.51cvss 7.8epss 0.01

    On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implementation of this exception, Node.js…

  • CVE-2024-23208HigJan 23, 2024
    risk 0.51cvss 7.8epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2024-0521HigJan 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Code Injection in paddlepaddle/paddle

  • CVE-2023-22514HigJan 16, 2024
    risk 0.51cvss 7.8epss 0.00

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of:…

  • CVE-2023-32383HigJan 10, 2024
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS Ventura 13.4. An app may be able to inject code into sensitive binaries bundled with Xcode.

  • CVE-2023-7224HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable

  • CVE-2023-6691HigDec 18, 2023
    risk 0.51cvss 7.8epss 0.00

    Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code execution and gain root privileges.

  • CVE-2023-6288HigDec 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.

  • CVE-2023-49314HigNov 28, 2023
    risk 0.51cvss 7.8epss 0.04

    Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

  • CVE-2023-48192HigNov 20, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.

  • CVE-2023-44141HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a specially crafted markdown file.

  • CVE-2023-46818HigOct 27, 2023
    risk 0.51cvss 7.2epss 0.16

    An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.

  • CVE-2023-43352HigOct 26, 2023
    risk 0.51cvss 7.8epss 0.01

    An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.

  • CVE-2023-28793HigOct 23, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.