Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Stsafe J Firmware MEDIUM 6.2
CVE-2021-43393

STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the E…

Mitigation only
Fix from $1,600 2022-03-04
Fedora HIGH 7.5
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…

Fix: 7.2.5+
Fix from $1,950 2022-02-24
October MEDIUM 5.3
CVE-2022-23655

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatur…

Fix: 1.0.475 / 1.1.11+
Fix from $1,600 2022-02-24
Emui MEDIUM 5.5
CVE-2021-40045

There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerab…

Fix: 2.0+
Fix from $1,600 2022-02-09
True Image HIGH 7.8
CVE-2022-24115

Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office …

Mitigation only
Fix from $1,950 2022-02-04
Rlc 410w Firmware HIGH 7.5
CVE-2022-21134

A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-c…

Mitigation only
Fix from $1,950 2022-01-28
Pac4j HIGH 7.5
CVE-2021-44878

If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an …

Fix: 4.5.5 / 5.3.1+
Fix from $1,950 2022-01-06
Tew 827dru Firmware MEDIUM 6.5
CVE-2021-20156

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is …

Mitigation only
Fix from $1,600 2021-12-30
Comprehensive Perl Archive Network HIGH 7.8
CVE-2020-16156

CPAN 2.28 allows Signature Verification Bypass.

No fix yet
Fix from $1,950 2021-12-13
Fedora HIGH 7.8
CVE-2020-16154

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

No fix yet
Fix from $1,950 2021-12-13
Ax210 Firmware MEDIUM 5.5
CVE-2021-0152

Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Win…

Fix: 22.60+
Fix from $1,600 2021-11-17
Zoom Client For Meetings HIGH 7.4
CVE-2021-34420

The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat ext…

Fix: 5.4.4+
Fix from $1,950 2021-11-11
Elixir Ecdsa CRITICAL 9.8
CVE-2021-43568

The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers…

No fix yet
Fix from $2,300 2021-11-09
Ecdsa Dotnet CRITICAL 9.8
CVE-2021-43569

The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers t…

No fix yet
Fix from $2,300 2021-11-09
Ecdsa Java CRITICAL 9.8
CVE-2021-43570

The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to …

No fix yet
Fix from $2,300 2021-11-09
Ecdsa Node CRITICAL 9.8
CVE-2021-43571

The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers …

No fix yet
Fix from $2,300 2021-11-09
Ecdsa Python CRITICAL 9.8
CVE-2021-43572

The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is n…

Fix: 2.0.1+
Fix from $2,300 2021-11-09
GitLab MEDIUM 5.3
CVE-2021-39909

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions st…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
Imanager Neteco 6000 Firmware HIGH 7.2
CVE-2021-37127

There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmwar…

Mitigation only
Fix from $1,950 2021-10-27
Openoffice HIGH 7.5
CVE-2021-41832

It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are…

Fix: 4.1.11+
Fix from $1,950 2021-10-11
Openoffice HIGH 7.5
CVE-2021-41830

It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice u…

Fix: 4.1.11+
Fix from $1,950 2021-10-11
Openoffice MEDIUM 5.3
CVE-2021-41831

It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users ar…

Fix: 4.1.11+
Fix from $1,600 2021-10-11
Portal For Arcgis HIGH 8.8
CVE-2021-29108

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a rem…

Fix: after 10.9
Fix from $1,950 2021-10-01
Mcafee Agent HIGH 7.3
CVE-2021-31841

A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsig…

Fix: 5.7.4+
Fix from $1,950 2021-09-22
Agent HIGH 7.8
CVE-2021-31847

Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL…

Fix: 5.7.4+
Fix from $1,950 2021-09-22
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37927

Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

Fix: 7.1+
Fix from $2,300 2021-09-22
Ios Xr MEDIUM 6.4
CVE-2021-34709

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NC…

Fix: 7.3.2 / 7.4.1+
Fix from $1,600 2021-09-09
Ios Xr MEDIUM 6.7
CVE-2021-34708

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NC…

Fix: 7.3.2 / 7.4.1+
Fix from $1,600 2021-09-09
Cortex Xsoar HIGH 8.1
CVE-2021-3051

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-…

Mitigation only
Fix from $1,950 2021-09-08
Ipados HIGH 7.5
CVE-2021-1849

An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchO…

Fix: 7.4 / 11.3+
Fix from $1,950 2021-09-08