CWE-913

Improper Control of Dynamically-Managed Code Resources

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

90 vulnerabilities with CWE-913
CVE-2023-29199 CRITICAL
vm2 <3.9.15 - Remote Code Execution
CVSS 9.8
CVE-2023-29017 CRITICAL
vm2 <3.9.15 - Remote Code Execution
CVSS 10.0
CVE-2023-25560 HIGH
DataHub < 0.8.45 - Authentication Bypass and System Account Creation via JSON Format String Injection
CVSS 8.2
CVE-2022-31764 HIGH
Apache ShardingSphere ElasticJob-UI <3.0.2 - RCE
CVSS 8.5
CVE-2022-4318 HIGH
cri-o < 1.26.0 - Arbitrary File Write via Environment Variable
CVSS 7.8
CVE-2022-43441 HIGH
Ghost sqlite3 5.0.0-5.1.1 - Remote Code Execution via Statement Bindings
CVSS 8.1
CVE-2022-44000 CRITICAL
BACKCLICK Professional <5.9.63 - RCE
CVSS 9.8
CVE-2022-3225 HIGH
GitHub budibase/budibase <1.3.20 - Info Disclosure
CVSS 8.8
CVE-2022-40635 MEDIUM
Crafter CMS 3.1.0-3.1.22 - Authenticated Remote Code Execution via Groovy Sandbox Bypass
CVSS 6.4
CVE-2022-40634 MEDIUM
Crafter CMS 3.1.0-3.1.22 - Authenticated Remote Code Execution via FreeMarker SSTI
CVSS 6.4
CVE-2022-36067 CRITICAL
vm2 <3.9.11 - Remote Code Execution
CVSS 10.0
CVE-2022-39051 MEDIUM
OTRS 6.0.0-6.0.31 and 7.0.0-7.0.36 - Remote Code Execution via Unverified Third-Party Package Installation
CVSS 6.8
CVE-2022-27889 MEDIUM
Palantir Foundry Multipass < 3.647.0 - Denial of Service via Authentication/Authorization Operations
CVSS 5.3
CVE-2022-25355 MEDIUM
EC-CUBE 3.0.0-3.0.18-p3 and 4.0.0-4.1.1 - Unauthenticated Email Spoofing via HTTP Host Header
CVSS 5.3
CVE-2022-25265 HIGH
Linux kernel <5.16.10 - Memory Corruption
CVSS 7.8
CVE-2021-23267 HIGH
Crafter CMS 3.1.0-3.1.17 - Authenticated Remote Code Execution via FreeMarker Static Methods
CVSS 7.6
CVE-2021-42809 MEDIUM
Thales Sentinel Protection Installer - Code Injection
CVSS 6.5
CVE-2021-23262 MEDIUM
CrafterCMS 3.1.0 through 3.1.13 - Remote Code Execution via YAML Configuration
CVSS 4.2
CVE-2021-23259 MEDIUM
Crafter CMS 3.1.0-3.1.11 - Authenticated Remote Code Execution via Groovy Script Rendering
CVSS 4.2
CVE-2021-23258 MEDIUM
Crafter CMS Spring SPEL - Authenticated OS Command Execution
CVSS 4.2
CVE-2021-32813 MEDIUM
Traefik < 2.4.13 - Header Manipulation via Connection Header Handling
CVSS 4.8
CVE-2021-22387 CRITICAL
Huawei EMUI and Magic UI - Remote Code Execution
CVSS 9.8
CVE-2021-32563 CRITICAL
Thunar < 4.16.7 and 4.17.x < 4.17.2 - Remote Code Execution via File Delegation
CVSS 9.8
CVE-2021-21413 HIGH
isolated-vm <4.0.0 - Info Disclosure
CVSS 8.0
CVE-2021-26276 MEDIUM
GoDaddy node-config-shield <0.2.2 - Code Injection
CVSS 5.3
Details
Vulnerabilities 90