CWE-417
9 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-417page 1 of 1
- CVE-2017-3969HIGHCVSS 8.2EG 5.92018-04-04
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL.
- CVE-2017-7760HIGHCVSS 7.8EG 7.82018-06-11
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter…
- CVE-2018-13906CRITICALCVSS 9.1EG 9.12019-06-14
The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forged application message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics …
- CVE-2018-14900HIGHCVSS 7.5EG 7.52018-08-30
On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print jobs directly to the printer via TCP port 9100.
- CVE-2018-5254HIGHCVSS 7.5EG 7.52018-04-12
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
- CVE-2018-6556LOWCVSS 3.3EG 3.32018-08-10
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. I…
- CVE-2018-8929HIGHCVSS 7.3EG 8.12018-07-06
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.
- CVE-2019-14318MEDIUMCVSS 5.9EG 5.92019-07-30
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. …
- CVE-2019-9855CRITICALCVSS 9.8EG 9.82019-09-06
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can …
Map vulnerabilities like CWE-417 to your infrastructure
EchelonGraph correlates every CVE — across CWE-417 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →