Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Redhat Upgrade Tool CRITICAL 9.8
CVE-2014-3585

redhat-upgrade-tool: Does not check GPG signatures when upgrading versions

Mitigation only
Fix from $2,300 2019-11-22
Debian Linux HIGH 8.8
CVE-2019-3465

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatur…

Fix: after 3.0.3
Fix from $1,950 2019-11-07
Junos HIGH 7.8
CVE-2019-0071

Veriexec is a kernel-based file integrity subsystem in Junos OS that ensures only authorized binaries are able to be executed. Due to a flaw in speci…

Mitigation only
Fix from $1,950 2019-10-09
Keybase HIGH 7.5
CVE-2019-16992

The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency at…

Mitigation only
Fix from $1,950 2019-09-30
Thunderbird HIGH 7.5
CVE-2019-11755

A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, althoug…

Fix: 68.1.1+
Fix from $1,950 2019-09-27
Ios Xe MEDIUM 6.7
CVE-2019-12662

A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege …

Mitigation only
Fix from $1,600 2019-09-25
Ios Xe MEDIUM 6.7
CVE-2019-12649

A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicio…

Mitigation only
Fix from $1,600 2019-09-25
Bsafe Cert J MEDIUM 6.5
CVE-2019-3738

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could p…

Fix: 6.2.5+
Fix from $1,600 2019-09-18
Libp2p HIGH 7.5
CVE-2019-15545

An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.

Fix: 0.8.1+
Fix from $1,950 2019-08-26
Fortios Ips Engine MEDIUM 5.9
CVE-2019-5592

Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine versi…

Fix: after 5.00006
Fix from $1,600 2019-08-23
Openpgpjs HIGH 7.5
CVE-2019-9153

Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with…

Fix: after 4.1.2
Fix from $1,950 2019-08-22
Openpgpjs HIGH 7.5
CVE-2019-9154

Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.

Fix: after 4.1.2
Fix from $1,950 2019-08-22
Keycloak HIGH 8.1
CVE-2019-10201

It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response …

Fix: after 6.0.1
Fix from $1,950 2019-08-14
Hima Al00b Firmware HIGH 7.8
CVE-2019-5299

Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vulnerability. Attackers can indu…

Mitigation only
Fix from $1,950 2019-08-13
Mdm9607 Firmware HIGH 7.8
CVE-2019-2278

User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto, Snapdragon Consumer IOT, Snap…

Patch available
Fix from $1,950 2019-07-25
Perl Crypt Jwt CRITICAL 9.8
CVE-2019-1010161

perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT sec…

Fix: after 0.022
Fix from $2,300 2019-07-25
Suricata HIGH 7.5
CVE-2019-1010279

Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An…

Fix: 4.1.3+
Fix from $1,950 2019-07-18
\ CRITICAL 9.8
CVE-2019-1010263

Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token…

Fix: 0.023+
Fix from $2,300 2019-07-17
Mailvelope MEDIUM 6.5
CVE-2019-9149

Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an …

Fix: 3.3.0+
Fix from $1,600 2019-07-09
Django Rest Registration CRITICAL 9.8
CVE-2019-13177

verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the D…

Fix: 0.5.0+
Fix from $2,300 2019-07-02
Ar1200 Firmware MEDIUM 6.7
CVE-2019-5300

There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 a…

Mitigation only
Fix from $1,600 2019-06-04
Crypto MEDIUM 5.9
CVE-2019-11841

A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to t…

No fix yet
Fix from $1,600 2019-05-22
Enigmail HIGH 7.5
CVE-2019-12269

Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" me…

Fix: 2.0.11+
Fix from $1,950 2019-05-21
Gpg Pgp MEDIUM 5.9
CVE-2019-8338

The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, w…

Fix: after 1.0
Fix from $1,600 2019-05-16
Website MEDIUM 5.9
CVE-2018-12556

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrar…

Fix: after 2018-06-05
Fix from $1,600 2019-05-16
Nx Os MEDIUM 6.7
CVE-2019-1809

A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…

Fix: 3.2 / 7.3+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1810

A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could al…

Fix: 7.0 / 9.2+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1811

A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…

Fix: 7.0 / 9.2+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1812

A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…

Fix: 7.0 / 9.2+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1813

A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…

Fix: 7.0 / 9.2+
Fix from $1,600 2019-05-15