CWE-494
Medium likelihoodDownload of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
204 vulnerabilities with CWE-494
CVE-2019-16760
MEDIUM
Cargo <Rust 1.26.0 - Info Disclosure
CVSS 4.6
CVE-2019-13534
HIGH
Philips IntelliVue - Code Injection
CVSS 7.2
CVE-2019-12809
HIGH
Yes24 Viewer ActiveX < 1.0.327.50126 - Remote Code Execution via Arbitrary File Download
CVSS 8.8
CVE-2019-12162
HIGH
Upwork Time Tracker <5.2.2.716 - Code Injection
CVSS 7.8
CVE-2019-5982
HIGH
VAIO Update < 7.3.0.03150 - Download of Code Without Integrity Check via Malicious Wireless LAN Access Point
CVSS 7.5
CVE-2019-7229
HIGH
ABB CP635 HMI - Unauthenticated Firmware Download Without Integrity Check
CVSS 8.3
CVE-2019-12728
HIGH
Grails < 3.3.10 - Cleartext HTTP Dependency Resolution
CVSS 8.1
CVE-2019-10249
HIGH
Xtext & Xtend <2.18.0 - Info Disclosure
CVSS 8.1
CVE-2019-3801
CRITICAL
Cloud Foundry cf-deployment < 7.9.0 - Cleartext Transmission of Sensitive Information
CVSS 9.8
CVE-2019-10248
HIGH
Eclipse Vorto <0.11 - Info Disclosure
CVSS 8.1
CVE-2019-10240
HIGH
Eclipse hawkBit < 0.3.0M2 - Cleartext Transmission of Sensitive Information via Maven Build Artifacts
CVSS 8.1
CVE-2018-5409
CRITICAL
PrinterLogic Print Management <18.3.1.96 - Code Injection
CVSS 9.8
CVE-2018-4009
HIGH
Shimo VPN - Privilege Escalation via Improper Code Signing Validation
CVSS 7.8
CVE-2018-19234
HIGH
COMPAREX Miss Marple Enterprise <2.0 - RCE
CVSS 8.8
CVE-2018-14620
MEDIUM
OpenStack RabbitMQ Container - SSRF
CVSS 4.7
CVE-2018-13012
HIGH
Safensoft Softcontrol Enterprise Suite < 4.4.12 - Download Without Integrity Check
CVSS 8.1
CVE-2017-12740
MEDIUM
Siemens LOGO! Soft Comfort < 8.2 - Remote Code Execution via Unprotected Software Package Download
CVSS 5.9
CVE-2017-2739
LOW
Huawei Vmall < 1.5.3.0 - Unauthenticated Code Download Integrity Failure
CVSS 3.1
CVE-2017-2707
HIGH
Huawei Mate 9 Firmware MHA-AL00AC00B125 - Privilege Escalation via Push Module Rich Media Message Handling
CVSS 7.1
CVE-2017-12306
MEDIUM
Cisco Spark Board - Privilege Escalation
CVSS 4.4
CVE-2017-13083
MEDIUM
Rufus < 2.17 - Improper Certificate Validation in Update Mechanism
CVSS 5.3
CVE-2016-6567
CRITICAL
SHDesigns Resident Download Manager - RCE
CVSS 9.8
CVE-2016-6564
HIGH
Multiple Android Firmware - Unauthenticated Remote Code Execution via OTA Update Mechanism
CVSS 8.1
CVE-2014-2378
Sensys Networks VSN240-F/VSN240-T <2.10.1/2.10.3 - RCE
CVE-2010-3440
MEDIUM
babiloo <2.0.11 - Local File Overwrite
CVSS 5.5
Details
Vulnerabilities
204
Exploit Likelihood
Medium