CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

200 vulnerabilities with CWE-494
CVE-2019-5982 HIGH
Sony Vaio Update < 7.3.0.03150 - Download Without Integrity Check
CVSS 7.5
CVE-2019-7229 HIGH
ABB CP635 HMI - Info Disclosure
CVSS 8.3
CVE-2019-12728 HIGH
Grails < 3.3.10 - Download Without Integrity Check
CVSS 8.1
CVE-2019-10249 HIGH
Xtext & Xtend <2.18.0 - Info Disclosure
CVSS 8.1
CVE-2019-3801 CRITICAL
Cloudfoundry Cf-deployment < 7.9.0 - Cleartext Transmission
CVSS 9.8
CVE-2019-10248 HIGH
Eclipse Vorto <0.11 - Info Disclosure
CVSS 8.1
CVE-2019-10240 HIGH
Eclipse Hawkbit < 0.2.5 - Cleartext Transmission
CVSS 8.1
CVE-2018-5409 CRITICAL
PrinterLogic Print Management <18.3.1.96 - Code Injection
CVSS 9.8
CVE-2018-4009 HIGH
Shimovpn Shimo VPN - Download Without Integrity Check
CVSS 7.8
CVE-2018-19234 HIGH
COMPAREX Miss Marple Enterprise <2.0 - RCE
CVSS 8.8
CVE-2018-14620 MEDIUM
OpenStack RabbitMQ Container - SSRF
CVSS 4.7
CVE-2018-13012 HIGH
Safensoft Softcontrol Enterprise Suite < 4.4.12 - Download Without Integrity Check
CVSS 8.1
CVE-2017-12740 MEDIUM
Siemens Logo! Soft Comfort < 8.2 - Data Authenticity Bypass
CVSS 5.9
CVE-2017-2739 LOW
Huawei Vmall < 1.5.3.0 - Download Without Integrity Check
CVSS 3.1
CVE-2017-2707 HIGH
Huawei Mate 9 Firmware - Download Without Integrity Check
CVSS 7.1
CVE-2017-12306 MEDIUM
Cisco Spark Board - Privilege Escalation
CVSS 4.4
CVE-2017-13083 MEDIUM
Rufus < 2.17 - Signature Verification Bypass
CVSS 5.3
CVE-2016-6567 CRITICAL
SHDesigns Resident Download Manager - RCE
CVSS 9.8
CVE-2016-6564 HIGH
Android - Rootkit
CVSS 8.1
CVE-2014-2378
Sensys Networks VSN240-F/VSN240-T <2.10.1/2.10.3 - RCE
CVE-2010-3440 MEDIUM
babiloo <2.0.11 - Local File Overwrite
CVSS 5.5
CVE-2008-3324 HIGH
PartyGaming PartyPoker <121/120 - RCE
CVSS 8.1
CVE-2008-3438 HIGH
Apple Mac OS X - Code Injection
CVSS 8.1
CVE-2002-0671 CRITICAL
Pingtel Xpressa Firmware - Download Without Integrity Check
CVSS 9.8
CVE-2001-1125 CRITICAL
Symantec LiveUpdate <1.6 - RCE
CVSS 9.8
Details
Vulnerabilities 200
Exploit Likelihood Medium