CWE-347
676 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (676)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreNov 21, 2024 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to by...Show more |
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files. |
Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write acces...Show more |
1Pivotal Software 1Spring Security Nov 21, 2024 May 13, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malici...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxNov 21, 2024 May 7, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Management CenterNov 26, 2024 May 6, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious softw...Show more |
1Titan 1Sf Rush Smart Band Firmware Nov 21, 2024 Apr 22, 2020 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted....Show more |
1Qualcomm 3Sda845 Firmware Sdm845 FirmwareSdm850 FirmwareNov 21, 2024 Apr 16, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SDM...Show more |
1Microsoft 1Research Javascript Cryptography Library Nov 21, 2024 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially...Show more |
1Lenovo 1System Interface Foundation Nov 21, 2024 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed. |
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-59...Show more |
2Apache Oracle2Graalvm NetbeansNov 21, 2024 Mar 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected b...Show more |
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow...Show more |
2Debian Ubuntu2Python Apt Python AptNov 21, 2024 Mar 26, 2020 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows download...Show more |
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgesture allows arbitrary applications to read or modify user-input logs. The Samsung ID is SVE-2019-14170 (June 2019). |
Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks. |
2Debian Golang2Debian Linux Package SshNov 21, 2024 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also,...Show more |
1Cisco 1Enterprise Network Function Virtualization Infrastructure Nov 21, 2024 Feb 19, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insuff...Show more |
1Linuxfoundation 1The Update Framework Nov 21, 2024 Feb 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. |
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3. |