CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2020-8133 MEDIUM
Nextcloud Server <19.0.1 - Info Disclosure
CVSS 5.3
CVE-2020-24439 LOW
Adobe Acrobat and Acrobat Reader DC < 20.012.20048 - Security Feature Bypass via Cryptographic Signature Verification
CVSS 2.8
CVE-2020-24429 HIGH
Acrobat Reader DC <2020.012.20048, 2020.001.30005, 2017.011.30175 -...
CVSS 7.7
CVE-2020-28045 HIGH
ProlinOS < 2.4.161.8859r - Unauthenticated Arbitrary Code Execution via Unsigned Shared Library
CVSS 7.8
CVE-2020-28042 MEDIUM
ServiceStack < 5.9.2 - JWT Signature Verification Bypass
CVSS 5.3
CVE-2020-11488 MEDIUM
Intel BMC Firmware < 3.38.30 - Improper Verification of Cryptographic Signature
CVSS 6.7
CVE-2020-15240 HIGH
omniauth-auth0 <2.4.1 - Auth Bypass
CVSS 7.4
CVE-2020-16922 MEDIUM
Windows - Spoofing via Improper File Signature Validation
CVSS 5.3
CVE-2020-12676 CRITICAL
FusionAuth fusionauth-samlv2 <0.2.3 - Auth Bypass
CVSS 9.1
CVE-2020-26540 HIGH
Foxit Reader & PhantomPDF <4.1 - Code Injection
CVSS 7.5
CVE-2020-15216 MEDIUM
goxmldsig < 1.1.0 - Cryptographic Signature Verification Bypass via Crafted XML File
CVSS 5.3
CVE-2020-14365 HIGH
Ansible Engine 2.8.0-2.8.14 and 2.9.0-2.9.12 - Improper Verification of Cryptographic Signature in DNF Module
CVSS 7.1
CVE-2020-25490 HIGH
sqreen/php_microagent < 1.16.0 - Remote Code Execution via Cryptographic Signature Verification Bypass
CVSS 7.3
CVE-2020-14515 HIGH
CodeMeter < 6.90 - Cryptographic Signature Verification Bypass via CmActLicense Update Files
CVSS 7.5
CVE-2020-10759 MEDIUM
Red Hat Enterprise Linux - PGP Signature Verification Bypass in fwupd
CVSS 6.0
CVE-2020-13593 HIGH
Texas Instruments SimpleLink CC2640R2 SDK < 2.2.3 - BLE Secure Manager Protocol Signature Bypass
CVSS 8.8
CVE-2020-13101 HIGH
OASIS Digital Signature Services 1.0 - Cryptographic Signature Verification Bypass via InlineXML Option
CVSS 7.5
CVE-2020-10126 HIGH
NCR SelfServ ATMs APTRA XFS 05.01.00 - Code Injection
CVSS 7.6
CVE-2020-1464 HIGH KEV
Windows - Spoofing via Improper File Signature Validation
CVSS 7.8
CVE-2020-15827 HIGH
JetBrains ToolBox 1.17-1.17.6856 - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2020-15957 HIGH
DP3T-Backend-SDK < 1.1.1 - Improper Verification of Cryptographic Signature via JWT alg=none Bypass
CVSS 7.5
CVE-2020-15705 MEDIUM
GRUB2 < 2.04 - Secure Boot Bypass via Improper Cryptographic Signature Verification
CVSS 6.4
CVE-2020-10608 HIGH
OSIsoft PI System - Privilege Escalation
CVSS 7.8
CVE-2020-13845 HIGH
Sylabs Singularity 3.0-3.5 - Improper Validation
CVSS 7.5
CVE-2020-15093 HIGH
tough < 0.7.1 - Cryptographic Signature Verification Bypass via Duplicate Signature
CVSS 8.6
Details
Vulnerabilities 686