CWE-354
170 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
CVEs (170)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
There is an Improper Validation of Integrity Check Value Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset. |
1Ibm 1Security Verify Privilege Manager Jun 17, 2026 Jun 25, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks. IBM X-Force ID: 184919. |
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app. |
3Alfa CiscoSiemens956gk5721 1fc00 0aa0 Firmware 6gk5721 1fc00 0ab0 Firmware6gk5722 1fc00 0aa0 Firmware+92 moreJun 17, 2026 May 11, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this t...Show more |
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange. |
1Proofpoint 1Enterprise Protection Jun 17, 2026 May 7, 2021 N/A· v4 6.3 MEDIUM· v3 6.8 MEDIUM· v2 Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The v...Show more |
1Nec 3Aterm Wf1200cr Firmware Aterm Wg1200cr FirmwareAterm Wg2600hs FirmwareJun 17, 2026 Apr 26, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier allows an att...Show more |
1Huawei 1Ais Bw80h 00 Firmware Jun 17, 2026 Feb 6, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 There is an insufficient integrity check vulnerability in Huawei Sound X Product. The system does not check certain software package's integrity sufficiently. Successful exploit could allow an attacker to load a crafted...Show more |
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades. |
1Dlink 10Dsr 1000 Firmware Dsr 1000ac FirmwareDsr 1000n Firmware+7 moreJun 17, 2026 Dec 15, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations b...Show more |
1Necplatforms 1Aterm Sa3500g Firmware Jun 17, 2026 Dec 14, 2020 N/A· v4 6.8 MEDIUM· v3 5.2 MEDIUM· v2 Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to execute a malicious program. |
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions. |
The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parse...Show more |
1Lightning Network Daemon Project 1Lightning Network Daemon Jun 17, 2026 Oct 21, 2020 N/A· v4 8.2 HIGH· v3 5.8 MEDIUM· v2 Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was alread...Show more |
1Lightning Network Daemon Project 1Lightning Network Daemon Jun 17, 2026 Oct 21, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open c...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum. |
1Lg 4Ipsfullhd Lg UltrawideLgpcsuite Setup+1 moreJun 17, 2026 Sep 14, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity...Show more |
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID...Show more |
hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verificati...Show more |
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file. |