Skip to main content

CWE archive

CWE-417 CVEs

Programmatic archive

15 CVEs tagged with CWE-4175 Critical, 6 High, 2 Medium, 2 Low, 0 Unrated.

CVE-2019-14318

Published Jul 30, 2019

Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousa…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14900

Published Aug 30, 2018

On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print jobs directly to the printer via TCP port 9100.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8929

Published Jul 6, 2018

Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct ma…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7760

Published Jun 11, 2018

The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malici…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5254

Published Apr 12, 2018

Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3969

Published Apr 4, 2018

Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages vi…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8822

Published Dec 3, 2017

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded desc…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-2712

Published Nov 22, 2017

S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check. An attacker may craft malformed pac…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000197

Published Nov 17, 2017

October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-6520

Published May 1, 2017

The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote att…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1