Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Nimbus Jose\+jwt HIGH 7.5
CVE-2017-12974

Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which a…

Patch available
Fix from $1,950 2017-08-20
Osci Transport Library MEDIUM 6.5
CVE-2017-10669

Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker wit…

Mitigation only
Fix from $1,600 2017-06-30
Android HIGH 7.8
CVE-2014-9934

A PKCS#1 v1.5 signature verification routine in all Android releases from CAF using the Linux kernel may not check padding.

Patch available
Fix from $1,950 2017-05-16
Iphone Os CRITICAL 9.8
CVE-2017-2423

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. The issue involves the "Security" c…

Fix: after 10.12.3
Fix from $2,300 2017-04-02
Virusscan Enterprise MEDIUM 5.0
CVE-2016-8021

Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote …

Fix: after 2.0.3
Fix from $1,600 2017-03-14
Openelec HIGH 8.1
CVE-2017-6445

The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed …

No fix yet
Fix from $1,950 2017-03-05
Firefox MEDIUM 5.0
CVE-2014-1498

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which a…

Fix: 2.25 / 28.0+
Fix from $1,600 2014-03-19
Windows 10 1507 MEDIUM 5.5
CVE-2013-3900 KEVEPSS 45%

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table an…

Patch available
Fix from $1,600 2013-12-11
Chrome MEDIUM 5.0
CVE-2011-3965

Google Chrome before 17.0.963.46 does not properly check signatures, which allows remote attackers to cause a denial of service (application crash) v…

Fix: 17.0.963.46+
Fix from $1,600 2012-02-09
Ip Phone 7940 Firmware HIGH 7.5
CVE-2005-2181

Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, w…

Mitigation only
Fix from $1,950 2005-07-11
Bt 100 Firmware HIGH 7.5
CVE-2005-2182

Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a …

Mitigation only
Fix from $1,950 2005-07-11
iOS HIGH 7.5
CVE-2002-1706

Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data O…

Fix: after 12.2
Fix from $1,950 2002-12-31
Chaivm Ezloader HIGH 7.8
CVE-2002-1796

ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which all…

Patch available
Fix from $1,950 2002-12-31