Vulnerabilities > Download of Code Without Integrity Check

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2021-3485 Download of Code Without Integrity Check vulnerability in Bitdefender Endpoint Security Tools 6.2.21.18
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution.
network
high complexity
bitdefender CWE-494
6.6
2020-12-03 CVE-2020-2320 Download of Code Without Integrity Check vulnerability in Jenkins Installation Manager Tool
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
network
low complexity
jenkins CWE-494
critical
9.8
2020-12-02 CVE-2020-25266 Download of Code Without Integrity Check vulnerability in Appimage Appimaged
AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage.
local
low complexity
appimage CWE-494
5.5
2020-11-24 CVE-2020-28332 Download of Code Without Integrity Check vulnerability in Barco Wepresent Wipg-1600W Firmware 2.5.1.8
Barco wePresent WiPG-1600W devices download code without an Integrity Check.
network
low complexity
barco CWE-494
critical
9.8
2020-11-19 CVE-2020-28213 Download of Code Without Integrity Check vulnerability in Schneider-Electric Ecostruxure Control Expert
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.
network
low complexity
schneider-electric CWE-494
8.8
2020-09-24 CVE-2020-15604 Download of Code Without Integrity Check vulnerability in Trendmicro products
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one.
network
low complexity
trendmicro CWE-494
7.5
2020-09-11 CVE-2020-1595 Download of Code Without Integrity Check vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input.
network
low complexity
microsoft CWE-494
critical
9.9
2020-09-11 CVE-2020-1576 Download of Code Without Integrity Check vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package.
network
high complexity
microsoft CWE-494
8.5
2020-09-11 CVE-2020-1453 Download of Code Without Integrity Check vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package.
network
low complexity
microsoft CWE-494
8.6
2020-09-11 CVE-2020-1452 Download of Code Without Integrity Check vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package.
network
low complexity
microsoft CWE-494
8.6