Vulnerabilities > Download of Code Without Integrity Check

DATE CVE VULNERABILITY TITLE RISK
2020-02-25 CVE-2020-8809 Download of Code Without Integrity Check vulnerability in Gurux Device Language Message Specification Director
Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection.
network
gurux CWE-494
6.8
2020-01-17 CVE-2020-5398 Download of Code Without Integrity Check vulnerability in multiple products
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
network
high complexity
vmware oracle netapp CWE-494
7.5
2019-11-12 CVE-2010-3440 Download of Code Without Integrity Check vulnerability in multiple products
babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.
3.3
2019-10-29 CVE-2019-3977 Download of Code Without Integrity Check vulnerability in Mikrotik Routeros
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature.
network
low complexity
mikrotik CWE-494
8.5
2019-10-10 CVE-2019-9534 Download of Code Without Integrity Check vulnerability in Cobham Explorer 710 Firmware 1.07
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image.
local
low complexity
cobham CWE-494
7.8
2019-10-08 CVE-2019-14845 Download of Code Without Integrity Check vulnerability in Redhat Openshift
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3.
high complexity
redhat CWE-494
5.3
2019-09-30 CVE-2019-16760 Download of Code Without Integrity Check vulnerability in Rust-Lang Rust
Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration key.
network
low complexity
rust-lang CWE-494
7.5
2019-09-12 CVE-2019-13534 Download of Code Without Integrity Check vulnerability in Philips products
Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C).
network
low complexity
philips CWE-494
6.5
2019-07-23 CVE-2019-12162 Download of Code Without Integrity Check vulnerability in Upwork Time Tracker 5.2.2.716
Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.
local
low complexity
upwork CWE-494
4.6
2019-07-05 CVE-2019-5982 Download of Code Without Integrity Check vulnerability in Sony Vaio Update 7.3.0.03150
Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point.
5.4