Vulnerabilities > Channel and Path Errors
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-09-06 | CVE-2019-9855 | Channel and Path Errors vulnerability in multiple products LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. | 9.8 |
2019-07-30 | CVE-2019-14318 | Channel and Path Errors vulnerability in Cryptopp Crypto++ Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. | 5.9 |
2019-06-14 | CVE-2018-13906 | Channel and Path Errors vulnerability in Qualcomm products The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forged application message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCA8081, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, SDX20, Snapdragon_High_Med_2016, SXR1130 | 9.1 |
2018-08-30 | CVE-2018-14900 | Channel and Path Errors vulnerability in Epson Wf-2750 Firmware Jp02L2 On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. | 7.5 |
2018-08-10 | CVE-2018-6556 | Channel and Path Errors vulnerability in multiple products lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. | 3.3 |
2018-07-06 | CVE-2018-8929 | Channel and Path Errors vulnerability in Synology SSL VPN Client Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload. | 8.1 |
2018-06-11 | CVE-2017-7760 | Channel and Path Errors vulnerability in Mozilla Firefox The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. | 7.8 |
2018-04-12 | CVE-2018-5254 | Channel and Path Errors vulnerability in Arista EOS Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message. | 7.5 |
2018-04-04 | CVE-2017-3969 | Channel and Path Errors vulnerability in Mcafee Network Security Manager Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL. | 5.9 |
2017-12-03 | CVE-2017-8822 | Channel and Path Errors vulnerability in multiple products In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012. | 3.7 |