CWE-347
732 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Simplesamlphp3Debian Linux Saml2SimplesamlphpJun 17, 2026 Mar 5, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forc...Show more |
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Iden...Show more |
3Arubanetworks DebianShibboleth3Clearpass Debian LinuxXmltooling CNov 21, 2024 Feb 27, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive inf...Show more |
The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generat...Show more |
2Debian Simplesamlphp2Debian Linux SimplesamlphpNov 21, 2024 Feb 2, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more than one signed asserti...Show more |
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwic...Show more |
2Debian Shibboleth2Debian Linux Xmltooling CNov 21, 2024 Jan 13, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensi...Show more |
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-j...Show more |
2Debian Enigmail2Debian Linux EnigmailMay 13, 2026 Dec 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actu...Show more |
2Debian Enigmail2Debian Linux EnigmailMay 13, 2026 Dec 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message...Show more |
1Cisco 2Nx Os Unified Computing SystemMay 13, 2026 Nov 30, 2017 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verific...Show more |
1Cisco 2Nx Os Unified Computing SystemMay 13, 2026 Nov 30, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verific...Show more |
1Huawei 1Fusionsphere Openstack May 13, 2026 Nov 22, 2017 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptographic signature. An attacker with high privilege may exploit th...Show more |
Huawei APP HiWallet earlier than 5.0.3.100 versions do not support signature verification for APK file. An attacker could exploit this vulnerability to hijack the APK and upload modified APK file. Successful exploit coul...Show more |
1Belden 1Tofino Xenon Security Appliance Firmware May 13, 2026 Nov 20, 2017 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned,...Show more |
2Debian Shibboleth2Debian Linux OpensamlMay 13, 2026 Nov 16, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform cri...Show more |
2Debian Shibboleth2Debian Linux Service ProviderMay 13, 2026 Nov 16, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform criti...Show more |
2Google Redhat4Chrome Enterprise Linux DesktopEnterprise Linux Server+1 moreMay 13, 2026 Oct 27, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly acc...Show more |
2Akeo Rufus Project2Rufus RufusMay 13, 2026 Oct 18, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code |
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments wher...Show more |