Latest CVE Feed
-
9.3
HIGHCVE-2016-10671
mystem-wrapper is a Yandex mystem app wrapper module. mystem-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an ... Read more
Affected Products : mystem-wrapper- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10672
cloudpub-redis is a module for CloudPub: Redis Backend cloudpub-redis downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an... Read more
Affected Products : cloudpub-redis- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10675
libsbmlsim is a module that installs linux binaries for libsbmlsim libsbmlsim downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources... Read more
Affected Products : libsbmlsim- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10676
rs-brightcove is a wrapper around brightcove's web api rs-brightcove downloads source file resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources wit... Read more
Affected Products : rs-brightcove- EPSS Score: %0.55
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10677
google-closure-tools-latest is a Node.js module wrapper for downloading the latest version of the Google Closure tools google-closure-tools-latest downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to caus... Read more
Affected Products : google-closure-tools-latest- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10678
serc.js is a Selenium RC process wrapper serc.js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled ... Read more
Affected Products : serc.js- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10683
arcanist downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or posit... Read more
Affected Products : arcanist- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10685
pk-app-wonderbox is an integration with wonderbox pk-app-wonderbox downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an at... Read more
Affected Products : pk-app-wonderbox- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10687
windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swap... Read more
Affected Products : windows-selenium-chromedriver- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10689
The windows-iedriver module downloads fixed version of iedriverserver.exe windows-iedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the reques... Read more
Affected Products : windows-iedriver- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10690
openframe-ascii-image module is an openframe plugin which adds support for ascii images via fim. openframe-ascii-image downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by sw... Read more
Affected Products : openframe-ascii-image- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10692
haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker contr... Read more
Affected Products : haxeshim- EPSS Score: %1.64
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10693
pm2-kafka is a PM2 module that installs and runs a kafka server pm2-kafka downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources wit... Read more
Affected Products : pm2-kafka- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10694
alto-saxophone is a module to install and launch Chromedriver for Mac, Linux or Windows. alto-saxophone versions below 2.25.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code executio... Read more
Affected Products : alto-saxophone- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10695
The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swa... Read more
Affected Products : npm-test-sqlite3-trunk- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10696
windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping o... Read more
Affected Products : windows-latestchromedriver- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10697
react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (R... Read more
Affected Products : react-native-baidu-voice-synthesizer- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-16035
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint... Read more
Affected Products : hubl-server- EPSS Score: %0.19
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-16040
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attack... Read more
Affected Products : gfe-sass- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-3578
Type mismatch for ie_len can cause the WLAN driver to allocate less memory on the heap due to implicit casting leading to a heap buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jun. 06, 2018
- Modified: Nov. 21, 2024