CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

658 vulnerabilities with CWE-345
CVE-2016-9450 HIGH
Drupal 8.x < 8.2.3 - Cache Poisoning via Password Reset Form
CVSS 7.5
CVE-2016-3677 MEDIUM
Huawei Wear App <15.0.0.307 - Info Disclosure
CVSS 6.5
CVE-2016-2309 HIGH
iRZ RUH2 < 2b - Authenticated Firmware Patch Modification
CVSS 7.2
CVE-2016-4554 HIGH
Oracle Linux < 3.5.17 - Data Authenticity Bypass
CVSS 8.6
CVE-2016-4553 HIGH
Canonical Ubuntu Linux < 3.5.17 - Data Authenticity Bypass
CVSS 8.6
CVE-2016-2346 HIGH
PL/SQL Developer < 11.0.6 - Remote Code Execution via Unverified Update Data
CVSS 8.1
CVE-2016-3983 HIGH
McAfee ATD <3.4.8.178 - Auth Bypass
CVSS 7.5
CVE-2016-1731 MEDIUM
Apple Software Update <2.2 - Info Disclosure
CVSS 5.9
CVE-2016-0818 MEDIUM
Conscrypt <4.4.4,5.1.1 LMY49H,6.0-2016-03-01 - Man-in-the-middle
CVSS 5.9
CVE-2016-1493 HIGH
Intel Driver Update Utility <2.4 - RCE
CVSS 7.5
CVE-2015-8371 HIGH
Composer <2016-02-10 - Cache Poisoning
CVSS 8.8
CVE-2015-5236 HIGH
IcedTea-Web - Same-Origin Policy Bypass via Spoofed Applet codebase
CVSS 7.5
CVE-2015-3956 CRITICAL
Hospira <13.4 - Unauthenticated RCE
CVSS 9.8
CVE-2015-9232 MEDIUM
Good for Enterprise 3.0.0.415 - Insufficient Verification of Data Authenticity in Authentication Delegation API
CVSS 5.3
CVE-2015-6854 CRITICAL
CA Single Sign-On R12.0 < SP3 CR13 / R12.5 < CR5 - DoS & Info Disclosure via Crafted Request
CVSS 9.1
CVE-2015-6853 CRITICAL
CA Single Sign-On Domino Web Agent - Denial of Service and Information Disclosure via Crafted Request
CVSS 9.1
CVE-2015-7539 HIGH
Jenkins < 1.640 and LTS < 1.625.2 - Unauthenticated Arbitrary Code Execution via Plugin Checksum Bypass
CVSS 7.5
CVE-2015-8254 MEDIUM
RSI Video Technologies Frontel Protocol < 2.0 - Unauthenticated Alarm Spoofing and Deactivation via MITM
CVSS 5.9
CVE-2015-2908
Mobile Devices C4 OBD-II Dongle Firmware < 3.4 - Remote Code Execution via Unvalidated Firmware Update
CVE-2015-3908
Ansible < 1.9.2 - Insufficient Verification of Data Authenticity in X.509 Certificate
CVE-2015-4674
TimeDoctor Pro 1.4.72.3 - Unauthenticated Remote Code Execution via Unsigned AutoUpdate
CVE-2015-0251
Apache Subversion 1.5.0-1.7.19 and 1.8.0-1.8.11 - Authenticated svn:author Property Spoofing via v1 HTTP Protocol
CVE-2015-0259
OpenStack Nova < 2014.1.4, 2014.2.x < 2014.2.3, kilo < kilo-3 - WebSocket Authentication Hijacking via Crafted Webpage
CVE-2014-5406
Hospira LifeCare PCA Infusion System < 7.0 - Unauthenticated Data Modification via Network Traffic
CVE-2014-8165
powerpc-utils - Remote Code Execution via Unsafe Pickle Deserialization
Details
Vulnerabilities 658