CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2019-5592 MEDIUM
FortiOS IPS Engine < 3.00547 - Padding Oracle Vulnerabilities via CBC Padding Implementation
CVSS 5.9
CVE-2019-9154 HIGH
Openpgpjs < 4.1.2 - Signature Verification Bypass
CVSS 7.5
CVE-2019-9153 HIGH
Openpgpjs < 4.1.2 - Signature Verification Bypass
CVSS 7.5
CVE-2019-10201 HIGH
Keycloak < 6.0.1 - Authentication Bypass via SAML Response Signature Removal
CVSS 8.1
CVE-2019-5299 HIGH
Huawei Hima-AL00B <HMA-AL00C00B175 - Code Injection
CVSS 7.8
CVE-2019-2278 HIGH
Snapdragon Auto/Mobile/IOT - Auth Bypass
CVSS 7.8
CVE-2019-1010161 CRITICAL
perl-CRYPT-JWT <0.022 - Auth Bypass
CVSS 9.8
CVE-2019-1010279 HIGH
Open Information Security Foundation Suricata <4.1.3 - DoS
CVSS 7.5
CVE-2019-1010263 CRITICAL
Perl Crypt::JWT <0.023 - Auth Bypass
CVSS 9.8
CVE-2019-9149 MEDIUM
Mailvelope < 3.3.0 - Unauthenticated Private Key Operations via Client-API URL Parameter
CVSS 6.5
CVE-2019-13177 CRITICAL
django-rest-registration < 0.5.0 - Improper Verification of Cryptographic Signature via Django Signing API Misuse
CVSS 9.8
CVE-2019-10136 MEDIUM
Red Hat Satellite and Spacewalk < 2.9 - Authenticated Session Validity Extension via Checksum Bypass
CVSS 4.3
CVE-2019-5300 MEDIUM
Huawei Routers - Digital Signature Verification Bypass
CVSS 6.7
CVE-2019-11841 MEDIUM
Supplementary Go cryptography libraries - Info Disclosure
CVSS 5.9
CVE-2019-12269 HIGH
Enigmail < 2.0.11 - PGP Signature Spoofing via Inline Message Manipulation
CVSS 7.5
CVE-2019-8338 MEDIUM
gpg-pgp < 1.0(9) - Improper Verification of Cryptographic Signature
CVSS 5.9
CVE-2019-1813 MEDIUM
Cisco NX-OS Software - Privilege Escalation
CVSS 6.7
CVE-2019-1812 MEDIUM
Cisco NX-OS Software - Privilege Escalation
CVSS 6.7
CVE-2019-1811 MEDIUM
Cisco NX-OS Software - Privilege Escalation
CVSS 6.7
CVE-2019-1810 MEDIUM
Cisco Nexus 3000/9000 - Privilege Escalation
CVSS 6.7
CVE-2019-1809 MEDIUM
Cisco NX-OS Software - Privilege Escalation
CVSS 6.7
CVE-2019-1808 MEDIUM
Cisco NX-OS Software - Privilege Escalation
CVSS 4.4
CVE-2019-1729 MEDIUM
Cisco NX-OS < 7.0(3)I4(9) - Authenticated Arbitrary File Write via Image Maintenance Command
CVSS 6.0
CVE-2019-1728 MEDIUM
Cisco NX-OS 8.1-8.1(1b) - Authenticated Arbitrary Command Execution via Persistent Configuration Storage
CVSS 6.7
CVE-2019-6318 CRITICAL
HP Color LaserJet CM4540 MFP < 2309010_581401 - Arbitrary Code Execution
CVSS 9.8
Details
Vulnerabilities 686