CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

687 vulnerabilities with CWE-347
CVE-2017-18122 HIGH
SimpleSAMLphp < 1.14.16 - Signature Validation Bypass via Multiple Signed Assertions
CVSS 8.1
CVE-2017-15090 MEDIUM
PowerDNS Recursor 4.0.0-4.0.6 - Improper Verification of Cryptographic Signature in DNSSEC Validation
CVSS 5.9
CVE-2017-17848 HIGH
Enigmail < 1.9.9 - Cryptographic Signature Spoofing via Multipart/Related Message Handling
CVSS 7.5
CVE-2017-17847 HIGH
Enigmail < 1.9.9 - Cryptographic Signature Spoofing via Attachment Handling
CVSS 7.5
CVE-2017-12333 MEDIUM
Cisco NX-OS System Software - Privilege Escalation
CVSS 6.7
CVE-2017-12331 MEDIUM
Cisco NX-OS System Software - Privilege Escalation
CVSS 6.7
CVE-2017-8190 MEDIUM
FusionSphere OpenStack V100R006C00SPC102(NFV) - Improper Verification of Cryptographic Signature
CVSS 6.7
CVE-2017-8177 MEDIUM
Huawei HiWallet < 5.0.3.100 - APK Hijacking via Missing Cryptographic Signature Verification
CVSS 5.3
CVE-2017-11400 MEDIUM
Belden Tofino Xenon Security Appliance Firmware < 3.1.0 - Improper Verification of Cryptographic Signature
CVSS 6.8
CVE-2017-16853 HIGH
OpenSAML < 2.6.1 - Improper Verification of Cryptographic Signature in DynamicMetadataProvider
CVSS 8.1
CVE-2017-16852 HIGH
Shibboleth Service Provider <2.6.1 - Info Disclosure
CVSS 8.1
CVE-2017-5066 MEDIUM
Google Chrome <58.0.3029 - Info Disclosure
CVSS 6.5
CVE-2017-13083 MEDIUM
Rufus < 2.17 - Improper Certificate Validation in Update Mechanism
CVSS 5.3
CVE-2017-12974 HIGH
Nimbus JOSE+JWT < 4.36 - Invalid Curve Attack via ECKey Construction
CVSS 7.5
CVE-2017-10669 MEDIUM
OSCI Transport Library 1.6.1 (Java) and 1.6 (.NET) - Signature Wrapping via Duplicate IDs
CVSS 6.5
CVE-2017-2423 CRITICAL
iPhone OS < 10.3 and macOS < 10.12.4 - Cryptographic Signature Verification Bypass via Empty Signature
CVSS 9.8
CVE-2017-6445 HIGH
OpenELEC 6.0.3, 7.0.1, 8.0.4 - Missing Encryption of Sensitive Data in Auto-Update Feature
CVSS 8.1
CVE-2016-20021 CRITICAL
Gentoo Portage <3.0.47 - Info Disclosure
CVSS 9.8
CVE-2016-7064 HIGH
pritunl-client < 1.0.1116.6 - Sensitive Information Leakage via Missing Cryptographic Signature Verification
CVSS 7.5
CVE-2016-11044 HIGH
Samsung Android L(5.0/5.1) and M(6.0) - Cryptographic Signature Verification Bypass
CVSS 7.8
CVE-2016-9604 MEDIUM
Linux Kernel < 4.11 - Incorrect Permission Assignment for Critical Resource
CVSS 4.4
CVE-2016-1000342 HIGH
Bouncy Castle JCE Provider <1.55 - Code Injection
CVSS 7.5
CVE-2016-1000338 HIGH
Bouncy Castle JCE Provider <1.55 - Code Injection
CVSS 7.5
CVE-2016-8021 MEDIUM
Intel Security VirusScan Enterprise Linux <2.0.3 - RCE
CVSS 5.0
CVE-2015-3298 HIGH
Yubico ykneo-openpgp <1.0.10 - Info Disclosure
CVSS 8.8
Details
Vulnerabilities 687