CWE-345
645 CVEs • Abstraction: Class
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CVEs (645)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request. |
1Allroundautomations 1Pl/sql Developer May 6, 2026 Apr 25, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying fields in the client-server data stream. |
McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process. |
The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of service (daemon crash) or...Show more |
The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before SP1 CR3 allows remote attackers to cause...Show more |
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream. |
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermed...Show more |
The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary cod...Show more |
Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file. |
1Rsi Video Technologies 1Frontel Protocol May 6, 2026 Dec 27, 2015 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Frontel protocol before 3 on RSI Video Technologies Videofied devices does not use integrity protection, which makes it easier for man-in-the-middle attackers to (1) initiate a false alarm or (2) deactivate an alarm...Show more |
1Mobile Devices 1C4 Obd Ii Dongle Firmware May 6, 2026 Aug 23, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifyi...Show more |
Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SS...Show more |
The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieved without use of SSL, which makes it easier for man-in-the-middle attackers to execute arbitrary cod...Show more |
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify...Show more |
2Async Http Client Project Redhat2Async Http Client Jboss FuseMay 6, 2026 Jun 24, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-...Show more |
2Async Http Client Project Redhat2Async Http Client Jboss FuseMay 6, 2026 Jun 24, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to...Show more |
5Apache AppleOpensuse+2 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+6 moreMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences. |
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for acces...Show more |
scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object. |