CWE-347
822 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (822)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Dell McafeeOracle16Application Performance Management Bsafe Cert JBsafe Crypto J+13 moreJun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into comput...Show more |
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures. |
1Fortinet 1Fortios Ips Engine Jun 17, 2026 Aug 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, 3.547 and below, whe...Show more |
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed. |
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature. |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Aug 14, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, an...Show more |
Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vulnerability. Attackers can induce users to install malicious applications. Due to a defect in the sign...Show more |
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279). |
1Qualcomm 15Mdm9607 Firmware Mdm9640 FirmwareSd 425 Firmware+12 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in MDM9607, MDM9640, SD 425, SD 427, SD 430, SD 435, SD 4...Show more |
1Perl Crypt Jwt Project 1Perl Crypt Jwt Jun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is: network c...Show more |
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed sequen...Show more |
Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attac...Show more |
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelo...Show more |
1Django Rest Registration Project 1Django Rest Registration Jun 17, 2026 Jul 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof t...Show more |
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extend...Show more |
1Huawei 11Ar1200 S Firmware Ar1200 FirmwareAr150 Firmware+8 moreJun 17, 2026 Jun 4, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected sof...Show more |
2Debian Golang2Crypto Debian LinuxJun 17, 2026 May 22, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleart...Show more |
Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text. |
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by cra...Show more |
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature...Show more |