Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Samlv2 CRITICAL 9.1
CVE-2020-12676

FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature el…

No fix yet
Fix from $2,300 2020-10-02
Foxit Reader HIGH 7.5
CVE-2020-26540

An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code …

Fix: 4.1+
Fix from $1,950 2020-10-02
Fedora MEDIUM 6.5
CVE-2020-15216

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypa…

Fix: 1.1.0+
Fix from $1,600 2020-09-29
Ansible Engine HIGH 7.1
CVE-2020-14365

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using …

Fix: after 3.7.2
Fix from $1,950 2020-09-23
Fmc1000 K9 Bios MEDIUM 6.6
CVE-2019-1736

A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible F…

Fix: 4.0.1f.0 / 4.0.2h+
Fix from $1,600 2020-09-23
Php Microagent HIGH 7.3
CVE-2020-25490

Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for ex…

Fix: 1.16.0+
Fix from $1,950 2020-09-17
Codemeter HIGH 7.5
CVE-2020-14515

CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature ch…

Fix: 6.90+
Fix from $1,950 2020-09-16
Enterprise Linux MEDIUM 6.0
CVE-2020-10759

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signatur…

No fix yet
Fix from $1,600 2020-09-15
Ipq6018 Firmware HIGH 7.8
CVE-2019-10562

u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into se…

Mitigation only
Fix from $1,950 2020-09-08
Simplelink Cc2640r2 Software Development Kit HIGH 8.8
CVE-2020-13593

The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows th…

Fix: after 2.2.3
Fix from $1,950 2020-08-31
Oasis Digital Signature Services HIGH 7.5
CVE-2020-13101

In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a valid or invalid outcome for a …

Mitigation only
Fix from $1,950 2020-08-24
Aptra Xfs HIGH 7.6
CVE-2020-10126

NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with ph…

Mitigation only
Fix from $1,950 2020-08-21
Windows 10 1507 HIGH 7.8
CVE-2020-1464 KEVEPSS 41%

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could b…

Patch available
Fix from $1,950 2020-08-17
Toolbox HIGH 7.5
CVE-2020-15827

In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.

Fix: 1.17.6856+
Fix from $1,950 2020-08-08
Dp3t Backend Software Development Kit HIGH 7.5
CVE-2020-15957

An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to chec…

Fix: 1.1.1+
Fix from $1,950 2020-07-30
Enterprise Linux Atomic Host MEDIUM 6.4
CVE-2020-15705

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the …

Fix: after 2.04
Fix from $1,600 2020-07-29
Pi Api HIGH 7.8
CVE-2020-10608

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libr…

Fix: after 4.8.0.18
Fix from $1,950 2020-07-24
Pritunl Client HIGH 7.5
CVE-2016-7064

A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage

Fix: 1.0.1116.6+
Fix from $1,950 2020-07-21
Singularity HIGH 7.5
CVE-2020-13845

Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforc…

Fix: after 3.5.0
Fix from $1,950 2020-07-14
Tough HIGH 8.6
CVE-2020-15093

The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker t…

Fix: 0.7.1+
Fix from $1,950 2020-07-09
P30 Firmware MEDIUM 5.5
CVE-2020-9226

HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper ch…

Fix: 10.1.0.135+
Fix from $1,600 2020-07-06
Tendermint MEDIUM 6.5
CVE-2020-15091

TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally …

Fix: 0.33.6+
Fix from $1,600 2020-07-02
Pan Os CRITICAL 10.0
CVE-2020-2021 KEV

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (uncheck…

Fix: 8.1.15 / 9.0.9+
Fix from $2,300 2020-06-29
Exacqvision Enterprise Manager HIGH 7.2
CVE-2020-9047EPSS 8%

A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service ve…

Fix: after 20.06.4.0
Fix from $1,950 2020-06-26
Recoverymanager HIGH 7.5
CVE-2020-15302

In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero…

Fix: 0xdc350d09f71c48c5d22fbe2741e4d6a03970e192+
Fix from $1,950 2020-06-25
Jsrsasign HIGH 7.5
CVE-2020-14966

An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows i…

Fix: after 8.0.18
Fix from $1,950 2020-06-22
Trezor Model T Firmware MEDIUM 6.5
CVE-2020-14199

BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two …

Fix: 1.9.1 / 2.3.1+
Fix from $1,600 2020-06-16
P5 Crypt Perl HIGH 8.8
CVE-2020-13895

Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small…

Fix: 0.32+
Fix from $1,950 2020-06-07
Phantompdf HIGH 7.5
CVE-2019-20834

An issue was discovered in Foxit PhantomPDF before 8.3.10. It allows signature validation bypass via a modified file or a file with non-standard sign…

Fix: 8.3.10+
Fix from $1,950 2020-06-04
Phantompdf HIGH 7.5
CVE-2019-20837

An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation bypass via a modified file or a file with non-stand…

Fix: 9.5+
Fix from $1,950 2020-06-04