CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

211 vulnerabilities with CWE-494
CVE-2017-2707 HIGH
Huawei Mate 9 Firmware MHA-AL00AC00B125 - Privilege Escalation via Push Module Rich Media Message Handling
CVSS 7.1
CVE-2017-12306 MEDIUM
Cisco Spark Board - Privilege Escalation
CVSS 4.4
CVE-2017-13083 MEDIUM
Rufus < 2.17 - Improper Certificate Validation in Update Mechanism
CVSS 5.3
CVE-2016-6567 CRITICAL
SHDesigns Resident Download Manager - RCE
CVSS 9.8
CVE-2016-6564 HIGH
Multiple Android Firmware - Unauthenticated Remote Code Execution via OTA Update Mechanism
CVSS 8.1
CVE-2014-2378
Sensys Networks VSN240-F/VSN240-T <2.10.1/2.10.3 - RCE
CVE-2010-3440 MEDIUM
babiloo <2.0.11 - Local File Overwrite
CVSS 5.5
CVE-2008-3324 HIGH
PartyGaming PartyPoker <121/120 - RCE
CVSS 8.1
CVE-2008-3438 HIGH
macOS < 10.5.4 - Remote Code Execution via Unverified Update
CVSS 8.1
CVE-2002-0671 CRITICAL
Pingtel xpressa_firmware 1.2.5-1.2.7.4 - Unauthenticated Trojan Horse Application Installation via DNS Spoofing
CVSS 9.8
CVE-2001-1125 CRITICAL
Symantec LiveUpdate < 1.6 - Remote Code Execution via DNS Spoofing
CVSS 9.8
Details
Vulnerabilities 211
Exploit Likelihood Medium