CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

658 vulnerabilities with CWE-345
CVE-2017-20180 MEDIUM
Zerocoin libzerocoin - Info Disclosure
CVSS 4.6
CVE-2017-17023 HIGH
NCP Secure Entry Client 10.11 r32792 - Unauthenticated Arbitrary Code Execution via Insecure Update Metadata
CVSS 8.1
CVE-2017-3224 HIGH
Quagga - Denial of Service via Crafted OSPF LSA with MaxSequenceNumber
CVSS 8.2
CVE-2017-3198 CRITICAL
GIGABYTE BRIX GB-BSi7H-6500 and GB-BXi7-5775 Firmware - Insufficient Firmware Image Verification
CVSS 9.8
CVE-2017-1405 MEDIUM
IBM Security Identity Manager Virtual Appliance 7.0 - Insufficient Verification of Data Authenticity
CVSS 4.4
CVE-2017-2667 HIGH
Hammer CLI < 0.10.0 - Improper Certificate Validation
CVSS 8.1
CVE-2017-1773 MEDIUM
IBM DataPower Gateway 7.1.0.0-7.1.0.19 - DNS Cache Poisoning via Spoofed DNS Responses
CVSS 4.0
CVE-2017-12740 MEDIUM
Siemens LOGO! Soft Comfort < 8.2 - Remote Code Execution via Unprotected Software Package Download
CVSS 5.9
CVE-2017-14091 HIGH
Trend Micro ScanMail for Exchange 12.0 - Privilege Escalation
CVSS 7.5
CVE-2017-2701 LOW
Huawei Mate 9 Firmware MHA-AL00AC00B125 - Denial of Service via Unverified Broadcasting Message
CVSS 3.3
CVE-2017-13083 MEDIUM
Rufus < 2.17 - Improper Certificate Validation in Update Mechanism
CVSS 5.3
CVE-2017-10624 HIGH
Juniper Networks Junos Space < 17.1R1 - Unauthenticated Database Modification via Node Certificate Spoofing
CVSS 7.5
CVE-2017-10862 MEDIUM
jwt-scala < 1.2.2 - Insufficient Verification of Data Authenticity
CVSS 5.3
CVE-2017-12972 HIGH
nimbus_jose+jwt - HMAC Bypass via Integer Overflow in Byte-to-Bit Conversion
CVSS 7.5
CVE-2017-7674 MEDIUM
Apache Tomcat <9.0.0.M21,8.5.15,8.0.44,7.0.78 - Info Disclosure
CVSS 4.3
CVE-2017-11379 HIGH
Trend Micro Deep Discovery Director 1.1 - Insufficient Verification of Data Authenticity in Backup Archives
CVSS 7.5
CVE-2017-11130 HIGH
StashCat < 1.7.5 (Android), < 0.0.80w (Web), < 0.0.86w (Desktop) - Replay Attacks
CVSS 8.1
CVE-2017-11103 HIGH
Heimdal < 7.4 - Remote Service Impersonation via Orpheus' Lyre Attack
CVSS 8.1
CVE-2017-11178 HIGH
FineCMS < 2017-05-12 - Arbitrary File Write via Style Controller
CVSS 7.5
CVE-2017-3219 HIGH
Acronis True Image <= 2017 Build 8053 - Unauthenticated Software Update Manipulation via HTTP
CVSS 8.8
CVE-2017-3218 HIGH
Samsung Magician < 5.1 - Improper Certificate Validation
CVSS 8.8
CVE-2017-9606 HIGH
Infotecs ViPNet Client and Coordinator <4.3.2-42442 - Privilege Escalation via Trojan Update
CVSS 7.3
CVE-2017-0563 HIGH
Linux Kernel - Elevation of Privilege via HTC Touchscreen Driver
CVSS 7.8
CVE-2016-1000004 CRITICAL
HHVM <3.9.5, 3.10.0-3.12.3, 3.13.0-3.14.1 - Code Injection
CVSS 9.8
CVE-2016-3016 MEDIUM
IBM Security Access Manager for Web 7.0 Firmware - Authenticated Code Execution via Unverified Update Processing
CVSS 4.4
Details
Vulnerabilities 658