CWE-417
15 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-417page 1 of 1
- CVE-2016-9879HIGHCVSS 7.5EG 7.52017-01-06
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with a…
- CVE-2017-1000197CRITICALCVSS 9.8EG 9.82017-11-17
October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.
- CVE-2017-2712MEDIUMCVSS 5.3EG 5.32017-11-22
S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check. An attacker may craft malformed packets and send them to a device to cause EFM flapping.
- CVE-2017-3969HIGHCVSS 8.2EG 8.22018-04-04
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL.
- CVE-2017-6520CRITICALCVSS 9.1EG 9.12017-05-01
The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) …
- CVE-2017-7480CRITICALCVSS 9.8EG 9.82017-07-21
rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.
- CVE-2017-7760HIGHCVSS 7.8EG 7.82018-06-11
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter…
- CVE-2017-8822LOWCVSS 3.7EG 3.72017-12-03
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a…
- CVE-2018-13906CRITICALCVSS 9.1EG 9.12019-06-14
The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forged application message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics …
- CVE-2018-14900HIGHCVSS 7.5EG 7.52018-08-30
On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print jobs directly to the printer via TCP port 9100.
- CVE-2018-5254HIGHCVSS 7.5EG 7.52018-04-12
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
- CVE-2018-6556LOWCVSS 3.3EG 3.32018-08-10
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. I…
- CVE-2018-8929HIGHCVSS 7.3EG 8.12018-07-06
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.
- CVE-2019-14318MEDIUMCVSS 5.9EG 5.92019-07-30
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. …
- CVE-2019-9855CRITICALCVSS 9.8EG 9.82019-09-06
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can …
Map vulnerabilities like CWE-417 to your infrastructure
EchelonGraph correlates every CVE — across CWE-417 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →