CWE-347
732 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack". |
1Foxitsoftware 2Foxit Reader PhantompdfJun 17, 2026 Oct 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur. |
2Fedoraproject Goxmldsig Project2Fedora GoxmldsigJun 17, 2026 Sep 29, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A...Show more |
2Debian Redhat5Ansible Engine Ansible TowerCeph Storage+2 moreJun 17, 2026 Sep 23, 2020 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even whe...Show more |
1Cisco 22Fmc1000 K9 Bios Fmc1000 K9 FirmwareFmc2500 K9 Bios+19 moreJun 17, 2026 Sep 23, 2020 N/A· v4 6.6 MEDIUM· v3 6.9 MEDIUM· v2 A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compr...Show more |
Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine. |
CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license fil...Show more |
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux...Show more |
1Qualcomm 28Ipq6018 Firmware Kamorta FirmwareMsm8998 Firmware+25 moreJun 17, 2026 Sep 8, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdra...Show more |
1Ti 1Simplelink Cc2640r2 Software Development Kit Jun 17, 2026 Aug 31, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connection pairing to be skipp...Show more |
1Oasis Open 1Oasis Digital Signature Services Jun 17, 2026 Aug 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a valid or invalid outcome for a valid or invalid signature) via a crafted XML signature, when the Inlin...Show more |
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restart the host computer a...Show more |
1Microsoft 18Windows 10 1507 Windows 10 1607Windows 10 1709+15 moreJun 17, 2026 Aug 17, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack...Show more |
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file. |
1Dp3t Backend Software Development Kit Project 1Dp3t Backend Software Development Kit Jun 17, 2026 Jul 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the sign...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure b...Show more |
1Osisoft 9Pi Api Pi Buffer SubsystemPi Connector+6 moreJun 17, 2026 Jul 24, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System sof...Show more |
A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage |
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signatu...Show more |
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a mi...Show more |