Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,510 CVEs tagged with CWE-31058 Critical, 302 High, 2,012 Medium, 138 Low, 0 Unrated.

CVE-2016-10633

Published Jun 1, 2018

dwebp-bin is a dwebp node.js wrapper that convert WebP into PNG. dwebp-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10632

Published Jun 1, 2018

apk-parser2 is a module which extracts Android Manifest info from an APK file. apk-parser2 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10631

Published Jun 1, 2018

jvminstall is a module for downloading and unpacking jvm to local system. jvminstall downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be po…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10629

Published Jun 1, 2018

nw-with-arm is a NW Installer including ARM-Build. nw-with-arm downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10626

Published Jun 1, 2018

mystem3 is a NodeJS wrapper for the Yandex MyStem 3. mystem3 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote c…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10622

Published Jun 1, 2018

nodeschnaps is a NodeJS compatibility layer for Java (Rhino). nodeschnaps downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to c…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10621

Published Jun 1, 2018

fibjs is a runtime for javascript applictions built on google v8 JS. fibjs downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10617

Published Jun 1, 2018

box2d-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requeste…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10615

Published Jun 1, 2018

curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It m…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10614

Published Jun 1, 2018

httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execut…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10613

Published Jun 1, 2018

bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10612

Published Jun 1, 2018

dalek-browser-ie-canary is Internet Explorer bindings for DalekJS. dalek-browser-ie-canary downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10610

Published Jun 1, 2018

unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 2,510 CVEsPage 7 of 101