CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

211 vulnerabilities with CWE-494
CVE-2020-5398 HIGH
Spring Framework 5.0.0-5.0.15, 5.1.0-5.1.12, 5.2.0-5.2.2 - Reflected File Download via Content-Disposition Header
CVSS 7.5
CVE-2019-19167 HIGH
Tobesoft Nexacro <2019.9.25.1 - RCE
CVSS 7.8
CVE-2019-19166 HIGH
Tobesoft XPlatform <9.2.3 - Code Injection
CVSS 7.8
CVE-2019-19165 HIGH
Inogard Ebiz4u <1.0.5.0 - Code Injection
CVSS 7.2
CVE-2019-3977 HIGH
MikroTik RouterOS < 6.44.5 and < 6.45.6 - Unauthenticated Arbitrary Code Download via Autoupgrade Feature
CVSS 7.5
CVE-2019-9534 HIGH
Cobham EXPLORER 710 <1.07 - Code Injection
CVSS 7.8
CVE-2019-14845 MEDIUM
OpenShift 4.1-4.3 - Man-in-the-Middle Attack via TLS Hostname Verification Bypass
CVSS 5.3
CVE-2019-16760 MEDIUM
Cargo <Rust 1.26.0 - Info Disclosure
CVSS 4.6
CVE-2019-13534 HIGH
Philips IntelliVue - Code Injection
CVSS 7.2
CVE-2019-12809 HIGH
Yes24 Viewer ActiveX < 1.0.327.50126 - Remote Code Execution via Arbitrary File Download
CVSS 8.8
CVE-2019-12162 HIGH
Upwork Time Tracker <5.2.2.716 - Code Injection
CVSS 7.8
CVE-2019-5982 HIGH
VAIO Update < 7.3.0.03150 - Download of Code Without Integrity Check via Malicious Wireless LAN Access Point
CVSS 7.5
CVE-2019-7229 HIGH
ABB CP635 HMI - Unauthenticated Firmware Download Without Integrity Check
CVSS 8.3
CVE-2019-12728 HIGH
Grails < 3.3.10 - Cleartext HTTP Dependency Resolution
CVSS 8.1
CVE-2019-10249 HIGH
Xtext & Xtend <2.18.0 - Info Disclosure
CVSS 8.1
CVE-2019-3801 CRITICAL
Cloud Foundry cf-deployment < 7.9.0 - Cleartext Transmission of Sensitive Information
CVSS 9.8
CVE-2019-10248 HIGH
Eclipse Vorto <0.11 - Info Disclosure
CVSS 8.1
CVE-2019-10240 HIGH
Eclipse hawkBit < 0.3.0M2 - Cleartext Transmission of Sensitive Information via Maven Build Artifacts
CVSS 8.1
CVE-2018-5409 CRITICAL
PrinterLogic Print Management <18.3.1.96 - Code Injection
CVSS 9.8
CVE-2018-4009 HIGH
Shimo VPN - Privilege Escalation via Improper Code Signing Validation
CVSS 7.8
CVE-2018-19234 HIGH
COMPAREX Miss Marple Enterprise <2.0 - RCE
CVSS 8.8
CVE-2018-14620 MEDIUM
OpenStack RabbitMQ Container - SSRF
CVSS 4.7
CVE-2018-13012 HIGH
Safensoft Softcontrol Enterprise Suite < 4.4.12 - Download Without Integrity Check
CVSS 8.1
CVE-2017-12740 MEDIUM
Siemens LOGO! Soft Comfort < 8.2 - Remote Code Execution via Unprotected Software Package Download
CVSS 5.9
CVE-2017-2739 LOW
Huawei Vmall < 1.5.3.0 - Unauthenticated Code Download Integrity Failure
CVSS 3.1
Details
Vulnerabilities 211
Exploit Likelihood Medium