Incomplete in the CWE catalog · 22 CVEs mapped
Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to code execution.
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (HTTP_*). The parser did not strictly reject dangerous control characters in header lines and header values, including CR, LF, and NUL, and did not consistently defend against encoded forms such as %0d, %0a, and %00. This can enable header value confusion across parser boundaries and may create unsafe data in the CGI execution context. This issue has been patched in version 2.04.
🚨 An improper process control in IBM AIX 7.2, 7.3, and VIOS 3.1, 4.1 can let attackers execute arbitrary commands remotely — that's like a chef getting access to the locked pantry and changing the entire menu without anyone noticing! 🔥 Think of it like a restaurant kitchen where the head chef has a secret key to the pantry and can change any recipe at will. The lack of proper controls allows an unwanted guest to slip in and whip up their own dish, potentially ruining everything! An attacker could run any command they choose, potentially leading to devastating consequences like data breaches, system failures, or unauthorized access to sensitive information. This is an absolute nightmare scenario for any organization, leaving the door wide open for major disruptions and damages!