CWE-347
676 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (676)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianPysaml2 Project3Debian Linux Pysaml2Ubuntu LinuxNov 21, 2024 Jan 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the nod...Show more |
2Python Ecdsa Project Redhat4Ceph Storage OpenstackPython Ecdsa+1 moreNov 21, 2024 Jan 2, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signatur...Show more |
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography. |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareNov 21, 2024 Dec 13, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user. |
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature. |
2Decentralized Anonymous Payment System Project Pivx2Decentralized Anonymous Payment System Private Instant Verified TransactionsNov 21, 2024 Dec 4, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations...Show more |
1Debian 2Advanced Package Tool Debian LinuxNov 21, 2024 Nov 26, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack. |
1Redhat 2Enterprise Linux Redhat Upgrade ToolNov 21, 2024 Nov 22, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 redhat-upgrade-tool: Does not check GPG signatures when upgrading versions |
3Debian SimplesamlphpXmlseclibs Project3Debian Linux SimplesamlphpXmlseclibsNov 21, 2024 Nov 7, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate o...Show more |
Veriexec is a kernel-based file integrity subsystem in Junos OS that ensures only authorized binaries are able to be executed. Due to a flaw in specific versions of Junos OS, affecting specific EX Series platforms, the V...Show more |
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar paymen...Show more |
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted...Show more |
1Cisco 52Ios Xe Nexus 3016 FirmwareNexus 3048 Firmware+49 moreNov 21, 2024 Sep 25, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signatu...Show more |
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. T...Show more |
3Dell McafeeOracle16Application Performance Management Bsafe Cert JBsafe Crypto J+13 moreNov 21, 2024 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into comput...Show more |
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures. |
1Fortinet 1Fortios Ips Engine Nov 21, 2024 Aug 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, 3.547 and below, whe...Show more |
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed. |
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature. |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Aug 14, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, an...Show more |