CWE-417 · 12 записей
Communication Channel Errors
CVE этого класса
12 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-9855Эксплойта нет | Windows 8.3 path equivalence handling flaw allows LibreLogo script executionlibreoffice · libreoffice · CWE-417 | Критическая9,8 | — | 2,6 % | 6 сент. 2019 г. |
39Наблюдать | CVE-2017-1000197Эксплойта нет | October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on octobercms · october · CWE-417 | Критическая9,8 | — | 1,2 % | 16 нояб. 2017 г. |
37Наблюдать | CVE-2017-6520Эксплойта нет | The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are bose · soundtouch 30 · CWE-417 | Критическая9,1 | — | 2,0 % | 30 апр. 2017 г. |
31Наблюдать | CVE-2017-7760Эксплойта нет | The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it.mozilla · firefox · CWE-417 | Высокая7,8 | — | 0,4 % | 11 июн. 2018 г. |
30Наблюдать | CVE-2016-9879Эксплойта нет | An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1.vmware · spring security · CWE-417 | Высокая7,5 | — | 1,4 % | 6 янв. 2017 г. |
30Наблюдать | CVE-2018-5254Эксплойта нет | Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDAarista · eos · CWE-417 | Высокая7,5 | — | 1,2 % | 12 апр. 2018 г. |
30Наблюдать | CVE-2018-14900Эксплойта нет | On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs.epson · wf-2750 firmware · CWE-417 | Высокая7,5 | — | 1,1 % | 30 авг. 2018 г. |
24Наблюдать | CVE-2019-14318Эксплойта нет | Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.cryptopp · crypto\+\+ · CWE-417 | Средняя5,9 | — | 2,7 % | 30 июл. 2019 г. |
23Наблюдать | CVE-2017-3969Эксплойта нет | SB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerabilitymcafee · network security manager · CWE-417 | Средняя5,9 | — | 0,8 % | 4 апр. 2018 г. |
21Наблюдать | CVE-2017-2712Эксплойта нет | S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency chehuawei · s3300 firmware · CWE-417 | Средняя5,3 | — | 1,1 % | 22 нояб. 2017 г. |
14Наблюдать | CVE-2017-8822Эксплойта нет | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays tor project · tor · CWE-417 | Низкая3,7 | — | 0,9 % | 3 дек. 2017 г. |
13Наблюдать | CVE-2018-6556Эксплойта нет | The lxc-user-nic component of LXC allows unprivileged users to open arbitrary filescanonical · ubuntu linux · CWE-417 | Низкая3,3 | — | 0,3 % | 10 авг. 2018 г. |
- CVE-2019-985540В плане
Windows 8.3 path equivalence handling flaw allows LibreLogo script execution
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libreoffice · libreoffice6 сент. 2019 г.
- CVE-2017-100019739Наблюдать
October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %octobercms · october16 нояб. 2017 г.
- CVE-2017-652037Наблюдать
The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %bose · soundtouch 3030 апр. 2017 г.
- CVE-2017-776031Наблюдать
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mozilla · firefox11 июн. 2018 г.
- CVE-2016-987930Наблюдать
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %vmware · spring security6 янв. 2017 г.
- CVE-2018-525430Наблюдать
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDA
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %arista · eos12 апр. 2018 г.
- CVE-2018-1490030Наблюдать
On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %epson · wf-2750 firmware30 авг. 2018 г.
- CVE-2019-1431824Наблюдать
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.
СредняяCVSS 5,9Эксплойта нетEPSS 3 %cryptopp · crypto\+\+30 июл. 2019 г.
- CVE-2017-396923Наблюдать
SB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerability
СредняяCVSS 5,9Эксплойта нетEPSS 1 %mcafee · network security manager4 апр. 2018 г.
- CVE-2017-271221Наблюдать
S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency che
СредняяCVSS 5,3Эксплойта нетEPSS 1 %huawei · s3300 firmware22 нояб. 2017 г.
- CVE-2017-882214Наблюдать
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays
НизкаяCVSS 3,7Эксплойта нетEPSS 1 %tor project · tor3 дек. 2017 г.
- CVE-2018-655613Наблюдать
The lxc-user-nic component of LXC allows unprivileged users to open arbitrary files
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %canonical · ubuntu linux10 авг. 2018 г.