Remote Code Execution

⚔️ Attack Types Related 19
slug: rce

Explanation

RCE (Remote Code Execution) は「攻撃者が遠隔から、サーバー上で任意のプログラムを実行できる」最も深刻な脆弱性です。 これが成立すると、サーバー全体が乗っ取られ、データ全削除・暗号通貨マイニング・ランサムウェア感染・他社攻撃の踏み台化など何でもされます。 セキュリティ業界では「最悪レベル」「最優先で塞ぐべき」と扱われます。
📌 Example
Log4Shell (CVE-2021-44228), Heartbleed (CVE-2014-0160) の後継 OpenSSL系, MOVEit Transfer (CVE-2023-34362) など。被害規模は数千億円〜兆円単位。

🔖 Related tags

🛡 Vulnerabilities tagged with this 2,172

ID Title
CVE-2020-1067 Buffer Overflow in microsoft (CVE-2020-1067)
CVE-2020-1069 Buffer Overflow in csharp (CVE-2020-1069)
CVE-2020-0901 Buffer Overflow in microsoft (CVE-2020-0901)
CVE-2020-1023 Unrestricted File Upload in microsoft (CVE-2020-1023)
CVE-2020-1024 Unrestricted File Upload in microsoft (CVE-2020-1024)
CVE-2020-1035 Buffer Overflow in microsoft (CVE-2020-1035)
CVE-2020-1037 Out-of-Bounds Write in microsoft (CVE-2020-1037)
CVE-2020-1051 Buffer Overflow in microsoft (CVE-2020-1051)
CVE-2020-9484 Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
CVE-2020-10673 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2019-12675 Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and...
CVE-2019-1068 KEV [KEV] Vulnerability in Microsoft sql-server (CVE-2019-1068)
CVE-2017-14854 Buffer Overflow in orpak (CVE-2017-14854)
CVE-2017-14853 The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attac...
CVE-2019-7386 Vulnerability in dos (CVE-2019-7386)
CVE-2018-18861 Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
CVE-2018-1258 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
CVE-2017-5641 Unsafe Deserialization in apache (CVE-2017-5641)
CVE-2017-15311 Buffer Overflow in dos (CVE-2017-15311)
CVE-2017-16717 Vulnerability in we-con (CVE-2017-16717)
CVE-2017-4933 Out-of-Bounds Write in vmware (CVE-2017-4933)
CVE-2017-4941 Buffer Overflow in vmware (CVE-2017-4941)
CVE-2017-11935 Buffer Overflow in microsoft (CVE-2017-11935)
CVE-2017-11885 Vulnerability in microsoft (CVE-2017-11885)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →