CWE-347
732 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten. |
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of th...Show more |
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashing sections by virtual address, in violation of...Show more |
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access. |
1F5 2Access Policy Manager Clients Big Ip Access Policy ManagerJun 17, 2026 Aug 2, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not eval...Show more |
3Fedoraproject RedhatSamba4Enterprise Linux FedoraSamba+1 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 pack...Show more |
1Belkin 1Wemo Smart Plug Wsp080 Firmware Jun 17, 2026 Jul 13, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to cause a Denial of Service (DoS) via a crafted firmware file. |
Mono Authenticode Validation Spoofing Vulnerability |
Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing crypt...Show more |
1Zoom 1Virtual Desktop Infrastructure Jun 17, 2026 Jun 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access...Show more |
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions. |
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6...Show more |
In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW). |
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed...Show more |
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40208. |
DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify th...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an u...Show more |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Apr 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Spoofing Vulnerability |
1Microsoft 8Windows 10 1507 Windows 10 1607Windows 10 1809+5 moreJun 17, 2026 Apr 11, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Windows Enroll Engine Security Feature Bypass Vulnerability |
1Veritas 2Aptare It Analytics Netbackup It AnalyticsJun 17, 2026 Mar 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A ma...Show more |