Auto-created placeholder
Volume of CVEs assigned to CWE-417 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7480CRITICAL rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution. | Jul 21, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-13906CRITICAL The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forged application message in Snapdragon Auto, Snapdragon Compute | Jun 14, 2019 | 9.1 | 29 | NO | NO |
CVE-2017-1000197CRITICAL October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server. | Nov 17, 2017 | 9.8 | 28 | NO | NO |
CVE-2019-9855CRITICAL LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launche | Sep 6, 2019 | 9.8 | 25 | NO | NO |
CVE-2018-14900HIGH On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print jobs directly to the printer via TCP port 9100. | Aug 30, 2018 | 7.5 | 25 | NO | NO |
CVE-2016-9879HIGH An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing | Jan 6, 2017 | 7.5 | 25 | NO | NO |
CVE-2018-8929HIGH Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man | Jul 6, 2018 | 8.1 | 24 | NO | NO |
CVE-2018-5254HIGH Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message. | Apr 12, 2018 | 7.5 | 23 | NO | NO |
CVE-2017-6520CRITICAL The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote atta | May 1, 2017 | 9.1 | 23 | NO | NO |
CVE-2019-14318MEDIUM Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousan | Jul 30, 2019 | 5.9 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.