CWE-347
732 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation. |
1Dell 3Alienware Command Center Application Command | UpdateUpdate/alienware UpdateJun 17, 2026 Aug 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability...Show more |
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow. |
showdoc is vulnerable to Missing Cryptographic Step |
1Swisslog Healthcare 1Hmi 3 Control Panel Firmware Jun 17, 2026 Aug 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptogr...Show more |
1Schneider Electric 6Evlink City Evc1s22p4 Firmware Evlink City Evc1s7p4 FirmwareEvlink Parking Ev.2 Firmware+3 moreJun 17, 2026 Jul 21, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0...Show more |
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the...Show more |
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed URLs by appending furt...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 7, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not oc...Show more |
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads an...Show more |
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird u...Show more |
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding anoth...Show more |
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of...Show more |
1Hitachi 1Id Bravura Security Fabric Jun 17, 2026 Jun 9, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. When using federated identity management (authenticating via SAML through a third-party identity pro...Show more |
1Bubble Fireworks Project 1Bubble Fireworks Jun 17, 2026 Jun 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package did not properly verify the signature of...Show more |
2Debian Inverse2Debian Linux SogoJun 17, 2026 Jun 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authent...Show more |
3Debian EntrouvertFedoraproject3Debian Linux FedoraLassoJun 17, 2026 Jun 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. |
1Schneider Electric 2Homelynk Firmware Spacelynk FirmwareJun 17, 2026 May 26, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device. |
1Schneider Electric 2Homelynk Firmware Spacelynk FirmwareJun 17, 2026 May 26, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code. |
1Ibm 2Power9 System Firmware Scale Out Lc System FirmwareJun 17, 2026 May 26, 2021 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process. |