CWE-347
732 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-...Show more |
1Korenix 42Jetnet 4508 W Firmware Jetnet 4508 FirmwareJetnet 4508f M Firmware+39 moreJun 17, 2026 Jan 9, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet device...Show more |
1Hitachienergy 3Relion 650 Firmware Relion 670 FirmwareRelion Sam600 Io FirmwareJun 17, 2026 Jan 4, 2024 N/A· v4 4.5 MEDIUM· v3 N/A· v2 A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vul...Show more |
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file
|
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file
|
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
|
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
|
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
|
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways....Show more |
1Zoom 4Meeting Software Development Kit Video Software Development KitVirtual Desktop Infrastructure+1 moreJun 17, 2026 Dec 13, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. |
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is configured to listen to multiple addresses or ports with each of them using different backend servers mana...Show more |
Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1. |
2Amd Intel6Radeon Pro Vega 56 Firmware Radeon Pro Vega 64 FirmwareRadeon Rx Vega 56 Firmware+3 moreJun 17, 2026 Nov 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arb...Show more |
2Amd Intel6Radeon Pro Vega 56 Firmware Radeon Pro Vega 64 FirmwareRadeon Rx Vega 56 Firmware+3 moreJun 17, 2026 Nov 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading t...Show more |
1Hanwhavision 3Pno A6081r E1t Firmware Pno A6081r E2t FirmwareWave Server SoftwareJun 17, 2026 Nov 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command...Show more |
Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the...Show more |
3Debian FedoraprojectVmware4Debian Linux FedoraOpen Vm Tools+1 moreJun 17, 2026 Oct 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CC...Show more |
2Browserify Debian2Browserify Sign Debian LinuxJun 17, 2026 Oct 26, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in `dsaVerify` function allow...Show more |
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105 |
Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. |