CWE-347
732 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Openstack2Keystone Ubuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Management CenterJun 17, 2026 May 6, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious softw...Show more |
1Titan 1Sf Rush Smart Band Firmware Jun 17, 2026 Apr 22, 2020 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted....Show more |
1Qualcomm 3Sda845 Firmware Sdm845 FirmwareSdm850 FirmwareJun 17, 2026 Apr 16, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SDM...Show more |
1Microsoft 1Research Javascript Cryptography Library Jun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially...Show more |
1Lenovo 1System Interface Foundation Jun 17, 2026 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed. |
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-59...Show more |
2Apache Oracle2Graalvm NetbeansJun 17, 2026 Mar 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected b...Show more |
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow...Show more |
2Debian Ubuntu2Python Apt Python AptJun 17, 2026 Mar 26, 2020 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows download...Show more |
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgesture allows arbitrary applications to read or modify user-input logs. The Samsung ID is SVE-2019-14170 (June 2019). |
Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks. |
2Debian Golang2Debian Linux Package SshJun 17, 2026 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also,...Show more |
1Cisco 1Enterprise Network Function Virtualization Infrastructure Jun 17, 2026 Feb 19, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insuff...Show more |
1Linuxfoundation 1The Update Framework Jun 17, 2026 Feb 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. |
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3. |
3Canonical DebianPysaml2 Project3Debian Linux Pysaml2Ubuntu LinuxJun 17, 2026 Jan 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the nod...Show more |
2Python Ecdsa Project Redhat4Ceph Storage OpenstackPython Ecdsa+1 moreJun 17, 2026 Jan 2, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signatur...Show more |
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography. |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user. |