CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
359 vulnerabilities with CWE-88
CVE-2018-11019
HIGH
Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 - Code Injection
CVSS 7.5
CVE-2018-17456
CRITICAL
Malicious Git HTTP Server For CVE-2018-17456
CVSS 9.8
CVE-2018-3856
CRITICAL
Samsung STH-ETH-250 Firmware 0.20.17 - OS Command Injection via RTSP URL Field
CVSS 9.9
CVE-2018-13386
HIGH
Sourcetree for Windows <2.6.9 - Command Injection
CVSS 8.1
CVE-2018-13385
CRITICAL
Sourcetree for macOS <2.7.6 - Command Injection
CVSS 9.8
CVE-2018-0345
HIGH
Cisco SD-WAN Solution - Command Injection
CVSS 8.8
CVE-2018-10992
CRITICAL
LilyPond 2.19.80 - Command Injection
CVSS 9.8
CVE-2017-15694
MEDIUM
Apache Geode <1.9.0 - Privilege Escalation
CVSS 6.5
CVE-2017-14591
CRITICAL
Atlassian Fisheye/Crucible <4.4.3 & 4.5.0 - Code Injection
CVSS 9.0
CVE-2017-1001003
CRITICAL
mathjs < 3.17.0 - Prototype Pollution via Unicode Character Bypass
CVSS 9.8
CVE-2016-1000222
HIGH
Logstash < 2.1.1 - Argument Injection via CSV Output
CVSS 7.5
CVE-2016-10033
CRITICAL
KEV
PHPMailer Sendmail Argument Injection
CVSS 9.8
CVE-2007-0882
Solaris 10 and 11 - Unauthenticated Argument Injection in telnetd via -f Sequence
CVE-2006-6597
HyperAccess 8.4 - Command Injection
CVE-2006-4692
Microsoft Windows XP <SP2 - Command Injection
CVE-2006-3015
WinSCP 3.8.1 - Argument Injection via Encoded Spaces in SCP/SFTP URI
CVE-2006-2312
Skype < 2.0.0.105 - Argument Injection via URI Handler
CVE-2006-2055
Microsoft Outlook 2003 SP1 - Command Injection
CVE-2006-2056
Internet Explorer 6 for Windows XP SP2 - Command Injection
CVE-2006-2057
Mozilla Firefox 1.0.6 - Command Injection
CVE-2006-2058
Avant Browser 10.1 Build 17 - Command Injection
CVE-2006-1865
Beagle < 0.2.5 - OS Command Injection via Crafted Filename Argument Injection
CVE-2005-4699
kimihia tellme < 1.2 - Argument Injection via q_Host Parameter
CVE-2004-0480
IBM Lotus Notes <6.5 - Command Injection
CVE-2004-0411
Konqueror < 3.2.2 - Command Injection via URI Handler Hostname
Details
Vulnerabilities
359