CWE-347
732 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature. |
2Decentralized Anonymous Payment System Project Pivx2Decentralized Anonymous Payment System Private Instant Verified TransactionsJun 17, 2026 Dec 4, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations...Show more |
1Debian 2Advanced Package Tool Debian LinuxNov 21, 2024 Nov 26, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack. |
1Redhat 2Enterprise Linux Redhat Upgrade ToolNov 21, 2024 Nov 22, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 redhat-upgrade-tool: Does not check GPG signatures when upgrading versions |
3Debian SimplesamlphpXmlseclibs Project3Debian Linux SimplesamlphpXmlseclibsJun 17, 2026 Nov 7, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate o...Show more |
Veriexec is a kernel-based file integrity subsystem in Junos OS that ensures only authorized binaries are able to be executed. Due to a flaw in specific versions of Junos OS, affecting specific EX Series platforms, the V...Show more |
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar paymen...Show more |
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted...Show more |
1Cisco 52Ios Xe Nexus 3016 FirmwareNexus 3048 Firmware+49 moreJun 17, 2026 Sep 25, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signatu...Show more |
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. T...Show more |
3Dell McafeeOracle16Application Performance Management Bsafe Cert JBsafe Crypto J+13 moreJun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into comput...Show more |
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures. |
1Fortinet 1Fortios Ips Engine Jun 17, 2026 Aug 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, 3.547 and below, whe...Show more |
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed. |
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature. |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Aug 14, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, an...Show more |
Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vulnerability. Attackers can induce users to install malicious applications. Due to a defect in the sign...Show more |
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279). |
1Qualcomm 15Mdm9607 Firmware Mdm9640 FirmwareSd 425 Firmware+12 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in MDM9607, MDM9640, SD 425, SD 427, SD 430, SD 435, SD 4...Show more |
1Perl Crypt Jwt Project 1Perl Crypt Jwt Jun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is: network c...Show more |