Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

688 CVEs tagged with CWE-34588 Critical, 272 High, 283 Medium, 45 Low, 0 Unrated.

CVE-2017-7674

Published Aug 11, 2017

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response vari…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11130

Published Aug 1, 2017

An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11178

Published Jul 12, 2017

In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via the contents and filename parameters in a route=style…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3219

Published Jun 21, 2017

Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3218

Published Jun 21, 2017

Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0563

Published Apr 7, 2017

An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3016

Published Feb 1, 2017

IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an au…

CVSS 4.4 · Medium

CVE-2016-9450

Published Nov 25, 2016

The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3677

Published Jun 13, 2016

The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPS…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2309

Published May 30, 2016

iRZ RUH2 before 2b does not validate firmware patches, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2346

Published Apr 25, 2016

Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3983

Published Apr 8, 2016

McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6854

Published Mar 24, 2016

The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to ca…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6853

Published Mar 24, 2016

The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1731

Published Mar 14, 2016

Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0818

Published Mar 12, 2016

The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 misha…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-7539

Published Feb 3, 2016

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1493

Published Jan 29, 2016

Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2015-8254

Published Dec 27, 2015

The Frontel protocol before 3 on RSI Video Technologies Videofied devices does not use integrity protection, which makes it easier for man-in-the-middle attackers to (1) initiate…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2908

Published Aug 23, 2015

Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attack…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 651-675 of 688 CVEsPage 27 of 28