CWE-347
676 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (676)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxDec 3, 2025 Sep 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field d...Show more |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxDec 3, 2025 Sep 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PK...Show more |
In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature verification. Consequently, a remote att...Show more |
2Debian Matrix2Debian Linux SynapseNov 21, 2024 Sep 18, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation. |
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a probl...Show more |
2Canonical Debian2Advanced Package Tool Ubuntu LinuxNov 21, 2024 Aug 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail. |
3Apple GoogleTi4Android Iphone OsMac Os X+1 moreMar 5, 2026 Aug 7, 2018 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic cu...Show more |
Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature...Show more |
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring....Show more |
1Gigabyte 2Gb Bsi7h 6500 Firmware Gb Bxi7 5775 FirmwareNov 21, 2024 Jul 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmw...Show more |
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, without a digital sign...Show more |
1Json Jwt Project 1Json Jwt Nov 21, 2024 Jun 26, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authe...Show more |
1Simple Password Store Project 1Simple Password Store Nov 21, 2024 Jun 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote a...Show more |
The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof ar...Show more |
1Carbonblack 1Carbon Black Cb Nov 21, 2024 Jun 13, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the th...Show more |
1Objective Development 1Little Snitch Nov 21, 2024 Jun 12, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architectures stored in a fat binary. An attacker...Show more |
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to heade...Show more |
2Bouncycastle Debian2Bc Java Debian LinuxMay 12, 2025 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and st...Show more |
4Bouncycastle CanonicalNetapp+1 more57 Mode Transition Tool Legion Of The Bouncy Castle Java Crytography ApiSatellite+2 moreMay 5, 2025 Jun 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and stil...Show more |
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a single node to sign a transaction and/or bloc...Show more |