CVE-2016-10637 affects haxe-dev, a cross-platform toolkit, due to its insecure practice of downloading binary resources over unencrypted HTTP. This vulnerability allows for Man-in-the-Middle (MITM) attacks, enabling an attacker to swap legitimate binaries with malicious ones, potentially leading to remote code execution (RCE). The CVSS score of 8.1 (High) indicates a significant risk, as it can be exploited remotely with high impact on confidentiality, integrity, and availability, though it requires high attack complexity. Currently, there is no evidence of active exploitation, and no public exploit code or significant community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:haxe:haxe-dev:-:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.