Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Nx Os MEDIUM 6.7
CVE-2019-1728

A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, lo…

Fix: 2.4.1.101 / 4.0+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.0
CVE-2019-1729

A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, loc…

Fix: 7.0+
Fix from $1,600 2019-05-15
Thunderbird MEDIUM 5.3
CVE-2018-18509

A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the sho…

Fix: 60.5.1+
Fix from $1,600 2019-04-26
Duo Network Gateway HIGH 7.5
CVE-2018-7340

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attack…

Fix: after 1.2.9
Fix from $1,950 2019-04-17
Color Laserjet Cm4540 Mfp Firmware CRITICAL 9.8
CVE-2019-6318

HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient…

Fix: 2309010_581401 / 2309010_581402+
Fix from $2,300 2019-04-11
Color Laserjet Cm4540 Mfp Firmware CRITICAL 9.8
CVE-2018-5923

In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking…

Fix: 2308974_579753 / 2308974_579754+
Fix from $2,300 2019-03-27
U Boot HIGH 7.0
CVE-2018-3968

An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions …

Fix: after 2014.07
Fix from $1,950 2019-03-21
Nx Os MEDIUM 6.7
CVE-2019-1615

A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…

Mitigation only
Fix from $1,600 2019-03-11
Enigmail MEDIUM 6.5
CVE-2018-15586

Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially …

Fix: 2.0.6+
Fix from $1,600 2019-02-11
Debian Linux MEDIUM 6.5
CVE-2018-15587

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a va…

Fix: after 3.28.2
Fix from $1,600 2019-02-11
Acrobat Dc MEDIUM 6.5
CVE-2018-16042EPSS 82%

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier vers…

Fix: after 19.008.20081
Fix from $1,600 2019-01-18
Simatic S7 400 Firmware HIGH 8.2
CVE-2018-16557

A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-40…

Fix: 6.0.9 / 8.2.1+
Fix from $1,950 2018-12-13
Starlink 2017 Firmware MEDIUM 6.4
CVE-2018-18203

A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (with physical access to the v…

No fix yet
Fix from $1,600 2018-11-28
Axtls MEDIUM 5.9
CVE-2018-16149

In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification blindly trusts the declared lengths in the ASN.1 …

Fix: after 2.1.3
Fix from $1,600 2018-11-07
Axtls MEDIUM 5.9
CVE-2018-16150

In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not reject excess data after the hash value.…

Fix: after 2.1.3
Fix from $1,600 2018-11-07
Axtls MEDIUM 5.9
CVE-2018-16253

In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not properly verify the ASN.1 metadata. Cons…

Fix: after 2.1.3
Fix from $1,600 2018-11-07
Gravityzone CRITICAL 9.8
CVE-2018-8955

The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remo…

No fix yet
Fix from $2,300 2018-10-24
Ios Xe MEDIUM 6.7
CVE-2018-15374

A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious softwa…

Mitigation only
Fix from $1,600 2018-10-05
Debian Linux HIGH 7.5
CVE-2018-16151

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GM…

Fix: 5.7.0+
Fix from $1,950 2018-09-26
Debian Linux HIGH 7.5
CVE-2018-16152

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GM…

Fix: 5.7.0+
Fix from $1,950 2018-09-26
Openswan HIGH 7.5
CVE-2018-15836

In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding strin…

Fix: 2.6.50.1+
Fix from $1,950 2018-09-26
Debian Linux HIGH 8.8
CVE-2018-16515

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction…

Fix: 0.33.3.1+
Fix from $1,950 2018-09-18
Libzypp HIGH 7.8
CVE-2018-7685

The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call woul…

Fix: 17.5.0+
Fix from $1,950 2018-08-31
Ubuntu Linux MEDIUM 5.9
CVE-2018-0501

The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verifica…

Fix: 1.6.4+
Fix from $1,600 2018-08-21
Wl18xx Bluetooth Service Pack MEDIUM 6.8
CVE-2018-5383

Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android version…

Fix: 4.3 / 10.13+
Fix from $1,600 2018-08-07
Samlbase HIGH 7.5
CVE-2018-5387

Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to ma…

Fix: 1.4.2+
Fix from $1,950 2018-07-24
Gb Bsi7h 6500 Firmware CRITICAL 9.8
CVE-2017-3198

GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are …

No fix yet
Fix from $2,300 2018-07-09
Diqee360 Firmware HIGH 7.8
CVE-2018-10988

An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the upda…

Mitigation only
Fix from $1,950 2018-07-05
Json Jwt MEDIUM 5.3
CVE-2018-1000539

Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM …

Fix: 1.9.4+
Fix from $1,600 2018-06-26
Simple Password Store CRITICAL 9.8
CVE-2018-12356

An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the outpu…

Fix: 1.7.2+
Fix from $2,300 2018-06-15