CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

171 vulnerabilities with CWE-354
CVE-2019-0071 HIGH
Junos OS 18.1R3-S4/18.3R1-S3 on EX2300/EX3400 - Authenticated Privilege Escalation via Veriexec
CVSS 7.8
CVE-2019-11753 HIGH
Firefox < 69 and Firefox ESR < 60.9 and >=68.0 < 68.1 - Privilege Escalation via Unprotected Installer Location
CVSS 7.8
CVE-2019-1163 MEDIUM
Windows 10 and Windows Server 2016/2019 - Security Feature Bypass via CAB File Signature Validation
CVSS 5.5
CVE-2019-10155 LOW
libreswan < 3.29 - Improper Validation of Integrity Check Value in IKEv1 Informational Exchange Packets
CVSS 3.1
CVE-2019-12097 HIGH
Telerik Fiddler <5.0.20182.28034 - Code Injection
CVSS 7.8
CVE-2018-21070 HIGH
Samsung Android N(7.x) and O(8.0) - Secure Boot Bypass via Missing Bootloader Integrity Check
CVSS 8.4
CVE-2018-6336 HIGH
osquery < 3.2.7 - Code Signing Bypass via Malicious Universal Binary
CVSS 7.8
CVE-2018-1000159 MEDIUM
tlslite-ng <0.7.3 - Improper Validation of Integrity Check Value
CVSS 5.9
CVE-2018-5382 MEDIUM
Bouncy Castle <1.47 - Integrity Compromise
CVSS 4.4
CVE-2018-5441 HIGH
PHOENIX CONTACT mGuard <8.6.0 - Info Disclosure
CVSS 7.8
CVE-2017-18689 HIGH
Samsung M(6.0)-N(7.0) - Auth Bypass
CVSS 7.5
CVE-2017-18649 HIGH
Samsung N(7.x) - Privilege Escalation
CVSS 7.2
CVE-2017-3224 HIGH
Quagga - Denial of Service via Crafted OSPF LSA with MaxSequenceNumber
CVSS 8.2
CVE-2017-15994 CRITICAL
rsync 3.1.3-development - Info Disclosure
CVSS 9.8
CVE-2017-3760 HIGH
Lenovo Service Framework - Remote Code Execution via Man-in-the-Middle Attack
CVSS 8.1
CVE-2017-12973 LOW
Nimbus JOSE+JWT <4.39 - Info Disclosure
CVSS 3.1
CVE-2017-9498 MEDIUM
Motorola MX011ANM/XR11-20 - Local Privilege Escalation
CVSS 5.5
CVE-2017-9606 HIGH
Infotecs ViPNet Client and Coordinator <4.3.2-42442 - Privilege Escalation via Trojan Update
CVSS 7.3
CVE-2017-4961 HIGH
Cloud Foundry Foundation BOSH Release <261.3 - Privilege Escalation
CVSS 8.8
CVE-2016-15028 MEDIUM
ICEPAY REST-API-NET <1.0 - Improper Validation
CVSS 4.8
CVE-2012-1170 HIGH
Moodle <2.2.2 - Privilege Escalation
CVSS 7.5
Details
Vulnerabilities 171
Exploit Likelihood Medium