CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

687 vulnerabilities with CWE-347
CVE-2018-16515 HIGH
Matrix Synapse < 0.33.3.1 - Improper Verification of Cryptographic Signature
CVSS 8.8
CVE-2018-7685 HIGH
libzypp < 17.5.0 - Improperly Implemented Security Check for Corrupted RPM Cache
CVSS 7.8
CVE-2018-0501 MEDIUM
Canonical Ubuntu Linux < 1.6.4 - Signature Verification Bypass
CVSS 5.9
CVE-2018-5383 MEDIUM
Android - Improper Verification of Cryptographic Signature in Bluetooth Key Exchange
CVSS 6.8
CVE-2018-5387 HIGH
Wizkunde SAMLBase - Info Disclosure
CVSS 7.5
CVE-2018-10988 HIGH
Diqee Diqee360 Firmware - Unauthenticated Remote Code Execution via Unsigned Firmware Update Script
CVSS 7.8
CVE-2018-1000539 MEDIUM
Nov json-jwt <1.9.4 - Code Injection
CVSS 5.3
CVE-2018-12356 CRITICAL
Simple Password Store <1.7.2 - Code Injection
CVSS 9.8
CVE-2018-12019 HIGH
Enigmail < 2.0.7 - Cryptographic Signature Spoofing via Crafted Primary User IDs
CVSS 7.5
CVE-2018-10407 MEDIUM
Carbon Black Cb Response - Code Injection
CVSS 5.5
CVE-2018-10470 MEDIUM
Little Snitch <4.0.6 - Code Injection
CVSS 5.3
CVE-2018-3756 HIGH
Hyperledger Iroha v1.0_beta & v1.0.0_beta-1 - Signature Verification Bypass
CVSS 7.5
CVE-2018-6664 MEDIUM
McAfee Data Loss Prevention Endpoint < 10.0.500 - Authenticated Application Protections Bypass via Command-Line Utility
CVSS 5.8
CVE-2018-4111 MEDIUM
macOS < 10.13.4 - S/MIME Encrypted Message Content Exposure via HTML Email
CVSS 5.9
CVE-2018-1000076 CRITICAL
RubyGems <2.7.6 - Improper Verification of Cryptographic Signature
CVSS 9.8
CVE-2018-7711 HIGH
SimpleSAMLphp < 1.15.4 - Improper Verification of Cryptographic Signature via Boolean Interpretation of Error Code
CVSS 8.1
CVE-2018-7644 HIGH
SimpleSAMLphp < 1.15.3 and saml2 < 1.10.5 - Improper Verification of Cryptographic Signature in XmlSecLibs
CVSS 7.5
CVE-2018-0489 MEDIUM
Shibboleth XMLTooling-C < 1.6.4 - Digital Signature Verification Bypass via Crafted XML Data
CVSS 6.5
CVE-2018-6459 MEDIUM
strongSwan 5.6.1 - Denial of Service via RSASSA-PSS Signature Without Mask Generation Function
CVSS 5.3
CVE-2018-0486 MEDIUM
Shibboleth XMLTooling-C < 1.6.3 - Improper Verification of Cryptographic Signature via Crafted DTD
CVSS 6.5
CVE-2018-0114 HIGH
Cisco node-jose < 0.11.0 - Unauthenticated Token Re-signing via Embedded Public Key
CVSS 7.5
CVE-2017-18407 MEDIUM
cPanel < 60.0.48 - Improper Verification of Cryptographic Signature for Support-Agreement Download
CVSS 4.8
CVE-2017-3198 CRITICAL
GIGABYTE BRIX GB-BSi7H-6500 and GB-BXi7-5775 Firmware - Insufficient Firmware Image Verification
CVSS 9.8
CVE-2017-16005 HIGH
joyent/http-signature <=0.9.11 - Header Forgery via Unsigned Header Names
CVSS 7.5
CVE-2017-18146 CRITICAL
Qualcomm Multiple Chipsets Firmware - Cryptographic Signature Verification Bypass
CVSS 9.8
Details
Vulnerabilities 687