Vulnerabilities > Download of Code Without Integrity Check

DATE CVE VULNERABILITY TITLE RISK
2008-08-01 CVE-2008-3438 Download of Code Without Integrity Check vulnerability in Apple mac OS X
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
network
high complexity
apple CWE-494
8.1
2002-07-23 CVE-2002-0671 Download of Code Without Integrity Check vulnerability in Pingtel Xpressa Firmware 1.2.5/1.2.7.4
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.
network
low complexity
pingtel CWE-494
critical
9.8
2001-10-05 CVE-2001-1125 Download of Code Without Integrity Check vulnerability in Symantec Liveupdate 1.0/1.4/1.5
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
network
low complexity
symantec CWE-494
critical
9.8