CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

687 vulnerabilities with CWE-347
CVE-2019-6318 CRITICAL
HP Color LaserJet CM4540 MFP < 2309010_581401 - Arbitrary Code Execution
CVSS 9.8
CVE-2019-1615 MEDIUM
Cisco NX-OS - Authenticated Cryptographic Signature Verification Bypass via Malicious Software Image
CVSS 6.7
CVE-2018-25099 CRITICAL
CryptX < 0.062 - Improper Verification of Cryptographic Signature
CVSS 9.8
CVE-2018-18689 MEDIUM
Multiple PDF Products - Signature Wrapping via /ByteRange and xref Manipulation
CVSS 5.3
CVE-2018-18688 MEDIUM
Multiple PDF Editors - Improper Verification of Cryptographic Signature via Incremental Saving
CVSS 5.3
CVE-2018-12556 MEDIUM
yarnpkg/website <2018-06-05 - Code Injection
CVSS 5.9
CVE-2018-18509 MEDIUM
Thunderbird < 60.5.1 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2018-7340 HIGH
Cisco Duo Network Gateway < 1.2.9 - Authentication Bypass via SAML Signature Manipulation
CVSS 7.5
CVE-2018-5923 CRITICAL
HP Color LaserJet CM4540 MFP Firmware < 2308974_579754 - Arbitrary Code Execution via Improper Signature Verification
CVSS 9.8
CVE-2018-3968 HIGH
U-Boot 2013.07-2014.07 - Cryptographic Signature Verification Bypass via Legacy Image Format
CVSS 7.0
CVE-2018-15587 MEDIUM
GNOME Evolution < 3.28.2 - OpenPGP Signature Spoofing via Crafted Email Attachment
CVSS 6.5
CVE-2018-15586 MEDIUM
Enigmail < 2.0.6 - Cryptographic Signature Spoofing via Multipart HTML Email
CVSS 6.5
CVE-2018-16042 MEDIUM
Adobe Acrobat and Reader DC < 15.006.30457, 15.008.20082-19.008.20081 - Cryptographic Signature Verification Bypass
CVSS 6.5
CVE-2018-16557 HIGH
SIMATIC S7-400 and S7-410 Firmware - Denial of Service via Crafted Packets to Port 102/tcp
CVSS 8.2
CVE-2018-18203 MEDIUM
Subaru StarLink Harman Head Units 2017-2019 - Unauthenticated Firmware Installation via Weak Signature Verification
CVSS 6.4
CVE-2018-1842 LOW
IBM Cognos Analytics 11.0.0.0-11.0.11.0 - Improper Verification of Cryptographic Signature in OIDC id_token
CVSS 3.6
CVE-2018-16253 MEDIUM
axtls < 2.1.3 - Cryptographic Signature Verification Bypass via ASN.1 Metadata
CVSS 5.9
CVE-2018-16150 MEDIUM
axtls < 2.1.3 - Cryptographic Signature Verification Bypass via PKCS#1 v1.5 Excess Data
CVSS 5.9
CVE-2018-16149 MEDIUM
axtls < 2.1.3 - Denial of Service via PKCS#1 v1.5 Signature Verification
CVSS 5.9
CVE-2018-18653 HIGH
Ubuntu Linux - Improper Verification of Cryptographic Signature
CVSS 7.8
CVE-2018-8955 CRITICAL
Bitdefender GravityZone - Remote Code Execution via Installer Filename Manipulation
CVSS 9.8
CVE-2018-15374 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.7
CVE-2018-16152 HIGH
strongSwan 4.x-5.x - Improper Verification of Cryptographic Signature via Excess Data in PKCS#1 v1.5
CVSS 7.5
CVE-2018-16151 HIGH
strongSwan 4.x-5.x - Cryptographic Signature Verification Bypass via Excess Data in PKCS#1 v1.5
CVSS 7.5
CVE-2018-15836 HIGH
Openswan < 2.6.50.1 - Improper Verification of Cryptographic Signature in PKCS#1 v1.5 RSA Implementation
CVSS 7.5
Details
Vulnerabilities 687