CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

651 vulnerabilities with CWE-347
CVE-2024-42220 HIGH
Microsoft Outlook - Signature Verification Bypass
CVSS 7.1
CVE-2024-42004 HIGH
Microsoft Teams - Signature Verification Bypass
CVSS 7.1
CVE-2024-41165 HIGH
Microsoft Word - Signature Verification Bypass
CVSS 7.1
CVE-2024-41159 HIGH
Microsoft Onenote - Signature Verification Bypass
CVSS 7.1
CVE-2024-41145 HIGH
Microsoft Teams - Signature Verification Bypass
CVSS 7.1
CVE-2024-41138 HIGH
Microsoft Teams - Signature Verification Bypass
CVSS 7.1
CVE-2024-39804 HIGH
Microsoft Powerpoint - Signature Verification Bypass
CVSS 7.1
CVE-2024-22461 HIGH
Dell RecoverPoint for VMs 6.0.x - Command Injection
CVSS 8.8
CVE-2024-54126 HIGH
TP-Link Archer C50 - RCE
CVE-2024-47476 HIGH
Dell NetWorker Management Console <19.11 - Code Injection
CVSS 7.8
CVE-2024-49413 HIGH
SmartSwitch <SMR Dec-2024 Release 1 - Info Disclosure
CVSS 7.1
CVE-2024-52958 HIGH
iota C.ai Conversational Platform <2.1.3 - Code Injection
CVSS 7.2
CVE-2024-53267 MEDIUM
Dev.sigstore Sigstore-java < 1.1.0 - Signature Verification Bypass
CVSS 5.5
CVE-2024-11696 MEDIUM
Mozilla Firefox and Thunderbird - Signature Validation Bypass via Exception Handling
CVSS 5.4
CVE-2024-40592 HIGH
FortiClient MacOS <7.4.0 - Code Injection
CVSS 7.5
CVE-2024-49394 MEDIUM
Mutt/neomutt - Info Disclosure
CVSS 5.3
CVE-2024-49393 MEDIUM
neomutt/mutt - Info Disclosure
CVSS 6.5
CVE-2024-47073 CRITICAL
DataEase <2.10.2 - Auth Bypass
CVSS 9.1
CVE-2024-51526 HIGH
hidebug - Info Disclosure
CVSS 8.2
CVE-2024-50347 MEDIUM
Laravel Reverb < 1.4.0 - Signature Verification Bypass
CVE-2024-8036 MEDIUM
ABB - DoS
CVSS 5.9
CVE-2024-48948 MEDIUM
Indutny Elliptic < 6.6.0 - Signature Verification Bypass
CVSS 4.8
CVE-2024-47943 CRITICAL
Rittal IoT Interface & CMC III Processing Unit - Code Injection
CVSS 9.8
CVE-2024-8531 HIGH
Data Center Expert - Code Injection
CVSS 7.2
CVE-2024-9487 CRITICAL
Github Enterprise Server < 3.11.16 - Signature Verification Bypass
CVSS 9.1
Details
Vulnerabilities 651