Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Enigmail HIGH 7.5
CVE-2018-12019

The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the s…

Fix: 2.0.7+
Fix from $1,950 2018-06-13
Carbon Black Cb MEDIUM 5.5
CVE-2018-10407

An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not com…

Mitigation only
Fix from $1,600 2018-06-13
Little Snitch MEDIUM 5.3
CVE-2018-10470

Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefor…

Fix: after 4.0.6
Fix from $1,600 2018-06-12
Http Signature HIGH 7.5
CVE-2017-16005

Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, …

Fix: after 0.9.11
Fix from $1,950 2018-06-04
Debian Linux HIGH 7.5
CVE-2016-1000342

In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible …

Fix: after 1.55
Fix from $1,950 2018-06-04
Satellite HIGH 7.5
CVE-2016-1000338

In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to…

Fix: 1.56+
Fix from $1,950 2018-06-01
Iroha HIGH 7.5
CVE-2018-3756

Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and b…

Mitigation only
Fix from $1,950 2018-06-01
Data Loss Prevention Endpoint HIGH 8.8
CVE-2018-6664

Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint befo…

Fix: 10.0.500 / 11.0.400+
Fix from $1,950 2018-05-25
Mdm9206 Firmware CRITICAL 9.8
CVE-2017-18146

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650…

Mitigation only
Fix from $2,300 2018-04-11
Mac Os X MEDIUM 5.9
CVE-2018-4111

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-mi…

Fix: 10.13.4+
Fix from $1,600 2018-04-03
Debian Linux CRITICAL 9.8
CVE-2018-1000076

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $2,300 2018-03-13
Debian Linux HIGH 8.1
CVE-2018-7711

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, a…

Fix: 1.10.6 / 1.15.4+
Fix from $1,950 2018-03-05
Simplesamlphp HIGH 7.5
CVE-2018-7644

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a rem…

Fix: 1.15.3+
Fix from $1,950 2018-03-05
Debian Linux MEDIUM 6.5
CVE-2018-0489

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatu…

Fix: 1.6.4 / 6.7.2+
Fix from $1,600 2018-02-27
Strongswan MEDIUM 5.3
CVE-2018-6459

The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial …

Mitigation only
Fix from $1,600 2018-02-20
Debian Linux HIGH 8.1
CVE-2017-18122

A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as v…

Fix: after 1.14.16
Fix from $1,950 2018-02-02
Recursor MEDIUM 5.9
CVE-2017-15090

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might …

Fix: after 4.0.6
Fix from $1,600 2018-01-23
Debian Linux MEDIUM 6.5
CVE-2018-0486

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signature…

Fix: 1.6.3+
Fix from $1,600 2018-01-13
Node Jose HIGH 7.5
CVE-2018-0114EPSS 43%

A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a ke…

Fix: 0.11.0+
Fix from $1,950 2018-01-04
Debian Linux HIGH 7.5
CVE-2017-17847

An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment s…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.5
CVE-2017-17848

An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages becau…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Nx Os MEDIUM 6.7
CVE-2017-12331

A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software …

Mitigation only
Fix from $1,600 2017-11-30
Nx Os MEDIUM 6.7
CVE-2017-12333

A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software …

Mitigation only
Fix from $1,600 2017-11-30
Hiwallet MEDIUM 5.3
CVE-2017-8177

Huawei APP HiWallet earlier than 5.0.3.100 versions do not support signature verification for APK file. An attacker could exploit this vulnerability …

Fix: 5.0.3.100+
Fix from $1,600 2017-11-22
Fusionsphere Openstack MEDIUM 6.7
CVE-2017-8190

FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the …

Mitigation only
Fix from $1,600 2017-11-22
Tofino Xenon Security Appliance Firmware MEDIUM 6.8
CVE-2017-11400

An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local…

Fix: after 3.1.0
Fix from $1,600 2017-11-20
Debian Linux HIGH 8.1
CVE-2017-16852

shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly conf…

Fix: 2.6.1+
Fix from $1,950 2017-11-16
Debian Linux HIGH 8.1
CVE-2017-16853

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly co…

Fix: 2.6.1+
Fix from $1,950 2017-11-16
Chrome MEDIUM 6.5
CVE-2017-5066

Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and…

Fix: 58.0.3029.81 / 58.0.3029.83+
Fix from $1,600 2017-10-27
Rufus HIGH 8.1
CVE-2017-13083

Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to …

Fix: after 2.17
Fix from $1,950 2017-10-18