CWE-417 · 12 records
Communication Channel Errors
CVEs in this class
12 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-9855No exploit | Windows 8.3 path equivalence handling flaw allows LibreLogo script executionlibreoffice · libreoffice · CWE-417 | Critical9.8 | — | 2.6% | Sep 6, 2019 |
39Monitor | CVE-2017-1000197No exploit | October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on octobercms · october · CWE-417 | Critical9.8 | — | 1.2% | Nov 16, 2017 |
37Monitor | CVE-2017-6520No exploit | The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are bose · soundtouch 30 · CWE-417 | Critical9.1 | — | 2.0% | Apr 30, 2017 |
31Monitor | CVE-2017-7760No exploit | The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it.mozilla · firefox · CWE-417 | High7.8 | — | 0.4% | Jun 11, 2018 |
30Monitor | CVE-2016-9879No exploit | An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1.vmware · spring security · CWE-417 | High7.5 | — | 1.5% | Jan 6, 2017 |
30Monitor | CVE-2018-5254No exploit | Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDAarista · eos · CWE-417 | High7.5 | — | 1.2% | Apr 12, 2018 |
30Monitor | CVE-2018-14900No exploit | On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs.epson · wf-2750 firmware · CWE-417 | High7.5 | — | 1.1% | Aug 30, 2018 |
24Monitor | CVE-2019-14318No exploit | Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.cryptopp · crypto\+\+ · CWE-417 | Medium5.9 | — | 2.7% | Jul 30, 2019 |
23Monitor | CVE-2017-3969No exploit | SB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerabilitymcafee · network security manager · CWE-417 | Medium5.9 | — | 0.8% | Apr 4, 2018 |
21Monitor | CVE-2017-2712No exploit | S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency chehuawei · s3300 firmware · CWE-417 | Medium5.3 | — | 1.1% | Nov 22, 2017 |
14Monitor | CVE-2017-8822No exploit | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays tor project · tor · CWE-417 | Low3.7 | — | 0.9% | Dec 3, 2017 |
13Monitor | CVE-2018-6556No exploit | The lxc-user-nic component of LXC allows unprivileged users to open arbitrary filescanonical · ubuntu linux · CWE-417 | Low3.3 | — | 0.3% | Aug 10, 2018 |
- CVE-2019-985540Plan
Windows 8.3 path equivalence handling flaw allows LibreLogo script execution
CriticalCVSS 9.8No exploitEPSS 3%libreoffice · libreofficeSep 6, 2019
- CVE-2017-100019739Monitor
October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on
CriticalCVSS 9.8No exploitEPSS 1%octobercms · octoberNov 16, 2017
- CVE-2017-652037Monitor
The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are
CriticalCVSS 9.1No exploitEPSS 2%bose · soundtouch 30Apr 30, 2017
- CVE-2017-776031Monitor
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it.
HighCVSS 7.8No exploitEPSS 0%mozilla · firefoxJun 11, 2018
- CVE-2016-987930Monitor
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1.
HighCVSS 7.5No exploitEPSS 1%vmware · spring securityJan 6, 2017
- CVE-2018-525430Monitor
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDA
HighCVSS 7.5No exploitEPSS 1%arista · eosApr 12, 2018
- CVE-2018-1490030Monitor
On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs.
HighCVSS 7.5No exploitEPSS 1%epson · wf-2750 firmwareAug 30, 2018
- CVE-2019-1431824Monitor
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.
MediumCVSS 5.9No exploitEPSS 3%cryptopp · crypto\+\+Jul 30, 2019
- CVE-2017-396923Monitor
SB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerability
MediumCVSS 5.9No exploitEPSS 1%mcafee · network security managerApr 4, 2018
- CVE-2017-271221Monitor
S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency che
MediumCVSS 5.3No exploitEPSS 1%huawei · s3300 firmwareNov 22, 2017
- CVE-2017-882214Monitor
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays
LowCVSS 3.7No exploitEPSS 1%tor project · torDec 3, 2017
- CVE-2018-655613Monitor
The lxc-user-nic component of LXC allows unprivileged users to open arbitrary files
LowCVSS 3.3No exploitEPSS 0%canonical · ubuntu linuxAug 10, 2018