CWE-494
209 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
CVEs (209)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary file download and execution. |
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malicious application may bypass Gatekeeper che...Show more |
This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Big Sur 11.3. A malicious application may bypass Gatekeeper checks. |
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587). |
Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could spoof the contents of an XML document describing an update package, replacing a downlo...Show more |
1Bitdefender 1Endpoint Security Tools Jun 17, 2026 May 24, 2021 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to ac...Show more |
1Secomea 1Gatemanager 8250 Firmware Jun 17, 2026 Mar 5, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prio...Show more |
1Jenkins 1Installation Manager Tool Jun 17, 2026 Dec 3, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads. |
AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it. |
1Barco 1Wepresent Wipg 1600w Firmware Jun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W firmware does not perform verification of digitally...Show more |
1Schneider Electric 1Ecostruxure Control Expert Jun 17, 2026 Nov 19, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending special...Show more |
1Trendmicro 5Antivirus+ 2019 Internet Security 2019Maximum Security 2019+2 moreJun 17, 2026 Sep 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an aff...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Sep 11, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in th...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Sep 11, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arb...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Sep 11, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arb...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Sep 11, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arb...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Sep 11, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arb...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Sep 11, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arb...Show more |
A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to download any file. The attacker is able to use startup menu directory via directory traversal for aut...Show more |
MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in downloading arbitrary files due to insufficient integrity verification of the file...Show more |