CWE-347
675 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (675)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectGnu+1 more4Active Iq Unified Manager Debian LinuxFedora+1 moreNov 21, 2024 Jan 16, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This fla...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits. |
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Port...Show more |
Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-...Show more |
1Korenix 42Jetnet 4508 W Firmware Jetnet 4508 FirmwareJetnet 4508f M Firmware+39 moreOct 8, 2025 Jan 9, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet device...Show more |
1Hitachienergy 3Relion 650 Firmware Relion 670 FirmwareRelion Sam600 Io FirmwareNov 21, 2024 Jan 4, 2024 N/A· v4 4.5 MEDIUM· v3 N/A· v2 A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vul...Show more |
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file
|
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file
|
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
|
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
|
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
|
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways....Show more |
1Zoom 4Meeting Software Development Kit Video Software Development KitVirtual Desktop Infrastructure+1 moreNov 21, 2024 Dec 13, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. |
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is configured to listen to multiple addresses or ports with each of them using different backend servers mana...Show more |
Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1. |
2Amd Intel6Radeon Pro Vega 56 Firmware Radeon Pro Vega 64 FirmwareRadeon Rx Vega 56 Firmware+3 moreFeb 13, 2025 Nov 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arb...Show more |
2Amd Intel6Radeon Pro Vega 56 Firmware Radeon Pro Vega 64 FirmwareRadeon Rx Vega 56 Firmware+3 moreFeb 13, 2025 Nov 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading t...Show more |
1Hanwhavision 3Pno A6081r E1t Firmware Pno A6081r E2t FirmwareWave Server SoftwareNov 21, 2024 Nov 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command...Show more |
Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the...Show more |
3Debian FedoraprojectVmware4Debian Linux FedoraOpen Vm Tools+1 moreMar 6, 2025 Oct 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CC...Show more |