← Back
CWE-345

645 CVEs • Abstraction: Class

Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

JSON object

Loading...

CVEs (645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
1Scanmail
May 13, 2026
Dec 16, 2017
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploited to overwrite sensitive files in the Sca...Show more
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploited to overwrite sensitive files in the ScanMail for Exchange directory.Show less
1Huawei
1Mate 9 Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the app...Show more
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of system unavailable.Show less
2Akeo
Rufus Project
2Rufus
Rufus
May 13, 2026
Oct 18, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code
1Juniper
1Junos Space
May 13, 2026
Oct 13, 2017
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to make unauthorized modifications to Space database or add nodes. Affected releases are Junip...Show more
Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to make unauthorized modifications to Space database or add nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.Show less
1Really
1Jwt Scala
May 13, 2026
Oct 12, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.
1Good
1Good For Enterprise
May 13, 2026
Sep 20, 2017
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect m...Show more
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.Show less
1Connect2id
1Nimbus Jose+jwt
May 13, 2026
Aug 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) a...Show more
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so that different plaintext is obtained for the same HMAC.Show less
1Apache
1Tomcat
May 13, 2026
Aug 11, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted cl...Show more
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.Show less
1Trendmicro
1Deep Discovery Director
May 13, 2026
Aug 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.
1Stashcat
1Heinekingmedia
May 13, 2026
Aug 1, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure confidentiality. In the whole protocol, n...Show more
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure confidentiality. In the whole protocol, no integrity or authenticity checks are done. Therefore man-in-the-middle attackers can conduct replay attacks.Show less
5Apple
DebianFreebsd+2 more
6Debian Linux
FreebsdHeimdal+3 more
May 13, 2026
Jul 13, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_tick...Show more
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.Show less
1Finecms Project
1Finecms
May 13, 2026
Jul 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via the contents and filename parameters in a route=style action. For example, this can be used to...Show more
In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via the contents and filename parameters in a route=style action. For example, this can be used to overwrite a .php file because the file extension is not checked.Show less
1Acronis
1True Image
May 13, 2026
Jun 21, 2017
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
1Samsung
1Magician
May 13, 2026
Jun 21, 2017
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
1Infotecs
2Vipnet Client
Vipnet Coordinator
May 13, 2026
Jun 15, 2017
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permission...Show more
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of integrity and authenticity checks.Show less
1Linux
1Linux Kernel
May 13, 2026
Apr 7, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the poss...Show more
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32089409.Show less
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 1, 2017
N/A· v4
4.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious co...Show more
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious code.Show less
1Drupal
1Drupal
May 6, 2026
Nov 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
1Huawei
2Hilink App
Wear App
May 6, 2026
Jun 13, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
1Irz
1Ruh2
May 6, 2026
May 30, 2016
N/A· v4
7.2 HIGH· v3
8.0 HIGH· v2
iRZ RUH2 before 2b does not validate firmware patches, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.