CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

687 vulnerabilities with CWE-347
CVE-2015-7336 HIGH
Lenovo System Update < 5.07.0008 - Cryptographic Signature Bypass
CVSS 7.5
CVE-2014-3585 CRITICAL
redhat-upgrade-tool - Improper Verification of Cryptographic Signature
CVSS 9.8
CVE-2014-9934 HIGH
Android - Improper Verification of Cryptographic Signature in PKCS#1 v1.5 Padding Check
CVSS 7.8
CVE-2014-1498
Suse Linux Enterprise Desktop < 2.25 - Signature Verification Bypass
CVE-2013-3900 MEDIUM KEV
Windows - Remote Code Execution via Authenticode Signature Verification Bypass
CVSS 5.5
CVE-2012-2092 MEDIUM
Ubuntu Cobbler < 2.2.2 - Security Bypass via GPG Signature Verification Error
CVSS 5.9
CVE-2011-3374 LOW
Debian Advanced Package Tool - Improper Verification of Cryptographic Signature
CVSS 3.7
CVE-2011-3965
Google Chrome < 17.0.963.46 - Denial of Service via Improper Cryptographic Signature Verification
CVE-2005-2181 HIGH
Cisco IP Phone 7940 and 7960 Firmware - Message Spoofing via Improper Cryptographic Signature Verification
CVSS 7.5
CVE-2005-2182 HIGH
Grandstream BT-100 Firmware - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2002-1706 HIGH
Cisco IOS 11.3-12.2 - Improper Verification of Cryptographic Signature in DOCSIS File
CVSS 7.5
CVE-2002-1796 HIGH
HP ChaiVM EZloader - Improper Verification of Cryptographic Signature
CVSS 7.8
Details
Vulnerabilities 687