CWE-347
822 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (822)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Carbonblack 1Carbon Black Cb Nov 21, 2024 Jun 13, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the th...Show more |
1Objective Development 1Little Snitch Nov 21, 2024 Jun 12, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architectures stored in a fat binary. An attacker...Show more |
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to heade...Show more |
2Bouncycastle Debian2Bc Java Debian LinuxMay 12, 2025 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and st...Show more |
4Bouncycastle CanonicalNetapp+1 more57 Mode Transition Tool Legion Of The Bouncy Castle Java Crytography ApiSatellite+2 moreMay 5, 2025 Jun 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and stil...Show more |
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a single node to sign a transaction and/or bloc...Show more |
1Mcafee 1Data Loss Prevention Endpoint Jun 17, 2026 May 25, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block acti...Show more |
1Qualcomm 28Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+25 moreNov 21, 2024 Apr 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD...Show more |
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML...Show more |
2Debian Rubygems2Debian Linux RubygemsNov 21, 2024 Mar 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verificat...Show more |
2Debian Simplesamlphp3Debian Linux Saml2SimplesamlphpJun 17, 2026 Mar 5, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forc...Show more |
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Iden...Show more |
3Arubanetworks DebianShibboleth3Clearpass Debian LinuxXmltooling CNov 21, 2024 Feb 27, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive inf...Show more |
The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generat...Show more |
2Debian Simplesamlphp2Debian Linux SimplesamlphpNov 21, 2024 Feb 2, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more than one signed asserti...Show more |
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwic...Show more |
2Debian Shibboleth2Debian Linux Xmltooling CNov 21, 2024 Jan 13, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensi...Show more |
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-j...Show more |
2Debian Enigmail2Debian Linux EnigmailMay 13, 2026 Dec 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actu...Show more |
2Debian Enigmail2Debian Linux EnigmailMay 13, 2026 Dec 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message...Show more |