← Back
CWE-494

209 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Download of Code Without Integrity Check

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

JSON object

Loading...

CVEs (209)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Vmall
May 13, 2026
Nov 22, 2017
N/A· v4
3.1 LOW· v3
2.9 LOW· v2
The upgrade package of Huawei Vmall APP Earlier than HwVmall 1.5.3.0 versions is transferred through HTTP. A man in the middle (MITM) can tamper with the upgrade package of Huawei Vmall APP, and to implant the malicious...Show more
The upgrade package of Huawei Vmall APP Earlier than HwVmall 1.5.3.0 versions is transferred through HTTP. A man in the middle (MITM) can tamper with the upgrade package of Huawei Vmall APP, and to implant the malicious applications.Show less
1Huawei
1Mate 9 Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Mate 9 smartphones with software MHA-AL00AC00B125 have a privilege escalation vulnerability in Push module. An attacker tricks a user to save a rich media into message on the smart phone, which could be exploited to caus...Show more
Mate 9 smartphones with software MHA-AL00AC00B125 have a privilege escalation vulnerability in Push module. An attacker tricks a user to save a rich media into message on the smart phone, which could be exploited to cause the attacker to delete message or fake user to send message.Show less
1Cisco
1Conference Director
May 13, 2026
Nov 16, 2017
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package, aka Signature Verification Bypass. The vulnerability is due to insufficie...Show more
A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package, aka Signature Verification Bypass. The vulnerability is due to insufficient upgrade package validation. An attacker could exploit this vulnerability by providing the upgrade process with an upgrade package that the attacker controls. An exploit could allow the attacker to install custom firmware to the Spark Board. Cisco Bug IDs: CSCvf84502.Show less
2Akeo
Rufus Project
2Rufus
Rufus
May 13, 2026
Oct 18, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code
1Sensysnetworks
4Trafficdot
VdsVsn240 F+1 more
May 6, 2026
Sep 5, 2014
N/A· v4
N/A· v3
7.6 HIGH· v2
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse u...Show more
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.Show less
1Party Gaming
1Party Poker Client
Apr 23, 2026
Aug 18, 2008
N/A· v4
8.1 HIGH· v3
7.6 HIGH· v2
The PartyGaming PartyPoker client program 121/120 does not properly verify the authenticity of updates, which allows remote man-in-the-middle attackers to execute arbitrary code via a Trojan horse update.
1Apple
1Mac Os X
Apr 23, 2026
Aug 1, 2008
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
1Pingtel
1Xpressa Firmware
Apr 16, 2026
Jul 23, 2002
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan...Show more
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.Show less
1Symantec
1Liveupdate
Apr 16, 2026
Oct 5, 2001
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.