Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Phantompdf HIGH 7.5
CVE-2020-13810

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-sta…

Fix: 9.7.2+
Fix from $1,950 2020-06-04
Phantompdf HIGH 7.5
CVE-2020-13803

An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypass via a modified file or a f…

Fix: 4.0+
Fix from $1,950 2020-06-04
Ios Xe MEDIUM 6.8
CVE-2020-3209

A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malic…

Patch available
Fix from $1,600 2020-06-03
Fastecdsa HIGH 7.5
CVE-2020-12607

An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. …

Fix: 2.1.2+
Fix from $1,950 2020-06-02
Controller HIGH 7.5
CVE-2020-13415

An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a con…

Fix: after 5.1
Fix from $1,950 2020-05-22
Whale Browser Installer CRITICAL 9.1
CVE-2020-9753

Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.

Fix: 2.6.88.19+
Fix from $2,300 2020-05-20
Fedora HIGH 7.5
CVE-2020-12244

An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not p…

Fix: after 4.3.0
Fix from $1,950 2020-05-19
Softpac Project MEDIUM 6.5
CVE-2020-12042

Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a resul…

Fix: after 9.6
Fix from $1,600 2020-05-14
Softpac Project MEDIUM 5.7
CVE-2020-12046

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to…

Fix: after 9.6
Fix from $1,600 2020-05-14
Spring Security HIGH 8.8
CVE-2020-5407

Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. Wh…

Fix: 5.2.4 / 5.3.2+
Fix from $1,950 2020-05-13
Ubuntu Linux MEDIUM 5.4
CVE-2020-12692

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An atta…

Fix: 15.0.1+
Fix from $1,600 2020-05-07
Sf Rush Smart Band Firmware HIGH 8.1
CVE-2020-11539

An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE sec…

No fix yet
Fix from $1,950 2020-04-22
Sda845 Firmware HIGH 7.8
CVE-2019-10575

Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer I…

Mitigation only
Fix from $1,950 2020-04-16
Research Javascript Cryptography Library CRITICAL 9.8
CVE-2020-1026

A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic…

Patch available
Fix from $2,300 2020-04-15
System Interface Foundation MEDIUM 5.5
CVE-2020-8324

A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow uns…

Fix: 1.2.184.31+
Fix from $1,600 2020-04-14
Android HIGH 7.8
CVE-2016-11044

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signa…

Mitigation only
Fix from $1,950 2020-04-07
Netbeans HIGH 7.5
CVE-2019-17561

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional c…

Fix: after 11.2
Fix from $1,950 2020-03-30
System Update HIGH 7.5
CVE-2015-7336

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 201…

Fix: after 5.07.0008
Fix from $1,950 2020-03-27
Android CRITICAL 9.1
CVE-2019-20597

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgesture allows arbitrary applications to read or modi…

Mitigation only
Fix from $2,300 2020-03-24
Mac HIGH 7.4
CVE-2020-2146

Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

Fix: after 1.1.0
Fix from $1,950 2020-03-09
Package Ssh HIGH 7.5
CVE-2020-9283EPSS 21%

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh pack…

No fix yet
Fix from $1,950 2020-02-20
Enterprise Network Function Virtualization Infrastructure MEDIUM 6.7
CVE-2020-3138

A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to inst…

Fix: after 3.11.1
Fix from $1,600 2020-02-19
The Update Framework CRITICAL 9.8
CVE-2020-6174

TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

Fix: after 0.12.1
Fix from $2,300 2020-02-05
Rider HIGH 7.5
CVE-2020-7906

In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in …

Mitigation only
Fix from $1,950 2020-01-30
Ubuntu Linux HIGH 7.5
CVE-2020-5390

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected…

Fix: 5.0.0+
Fix from $1,950 2020-01-13
Ceph Storage CRITICAL 9.1
CVE-2019-14859

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver…

Fix: 0.13.3+
Fix from $2,300 2020-01-02
Wolfssl HIGH 7.5
CVE-2019-19962

wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.

Fix: 4.3.0+
Fix from $1,950 2019-12-25
Petalk Ai Firmware HIGH 8.1
CVE-2019-16732

Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root use…

No fix yet
Fix from $1,950 2019-12-13
Ubuntu Cobbler MEDIUM 5.9
CVE-2012-2092

A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG sign…

Fix: 2.2.2+
Fix from $1,600 2019-12-06
Decentralized Anonymous Payment System HIGH 7.5
CVE-2019-16753

An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation…

Fix: after 2019-08-26
Fix from $1,950 2019-12-04