Vulnerabilities (CVE)

Filtered by CWE-88
Total 446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0907 1 Microsoft 2 Windows Server 2003, Windows Xp 2026-06-16 5.1 MEDIUM N/A
Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.
CVE-2002-0985 2 Openpkg, Php 2 Openpkg, Php 2026-06-16 7.5 HIGH N/A
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
CVE-2001-1246 1 Php 1 Php 2026-06-16 7.5 HIGH N/A
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.
CVE-2001-0667 1 Microsoft 1 Internet Explorer 2026-06-16 7.5 HIGH 7.3 HIGH
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.
CVE-2001-0150 1 Microsoft 1 Internet Explorer 2026-06-16 5.1 MEDIUM N/A
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.
CVE-1999-0113 1 Ibm 1 Aix 2026-06-16 10.0 HIGH N/A
Some implementations of rlogin allow root access if given a -froot parameter.