Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
MEDIUM 6.2 CVE-2021-43393 STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the E… Stsafe J Firmware Mitigation only Fix from $1,6002022-03-04 HIGH 7.5 CVE-2021-25636 LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur… Fedora 7.2.5+ Fix from $1,9502022-02-24 MEDIUM 5.3 CVE-2022-23655 Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatur… October 1.0.475 / 1.1.11+ Fix from $1,6002022-02-24 MEDIUM 5.5 CVE-2021-40045 There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerab… Emui 2.0+ Fix from $1,6002022-02-09 HIGH 7.8 CVE-2022-24115 Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office … True Image Mitigation only Fix from $1,9502022-02-04 HIGH 7.5 CVE-2022-21134 A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-c… Rlc 410w Firmware Mitigation only Fix from $1,9502022-01-28 HIGH 7.5 CVE-2021-44878 If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an … Pac4j 4.5.5 / 5.3.1+ Fix from $1,9502022-01-06 MEDIUM 6.5 CVE-2021-20156 Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is … Tew 827dru Firmware Mitigation only Fix from $1,6002021-12-30 HIGH 7.8 CVE-2020-16156 CPAN 2.28 allows Signature Verification Bypass. Comprehensive Perl Archive Network No fix yet Fix from $1,9502021-12-13 HIGH 7.8 CVE-2020-16154 The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass. Fedora No fix yet Fix from $1,9502021-12-13 MEDIUM 5.5 CVE-2021-0152 Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Win… Ax210 Firmware 22.60+ Fix from $1,6002021-11-17 HIGH 7.4 CVE-2021-34420 The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat ext… Zoom Client For Meetings 5.4.4+ Fix from $1,9502021-11-11 CRITICAL 9.8 CVE-2021-43568 The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers… Elixir Ecdsa No fix yet Fix from $2,3002021-11-09 CRITICAL 9.8 CVE-2021-43569 The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers t… Ecdsa Dotnet No fix yet Fix from $2,3002021-11-09 CRITICAL 9.8 CVE-2021-43570 The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to … Ecdsa Java No fix yet Fix from $2,3002021-11-09 CRITICAL 9.8 CVE-2021-43571 The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers … Ecdsa Node No fix yet Fix from $2,3002021-11-09 CRITICAL 9.8 CVE-2021-43572 The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is n… Ecdsa Python 2.0.1+ Fix from $2,3002021-11-09 MEDIUM 5.3 CVE-2021-39909 Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions st… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 HIGH 7.2 CVE-2021-37127 There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmwar… Imanager Neteco 6000 Firmware Mitigation only Fix from $1,9502021-10-27 HIGH 7.5 CVE-2021-41832 It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are… Openoffice 4.1.11+ Fix from $1,9502021-10-11 HIGH 7.5 CVE-2021-41830 It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice u… Openoffice 4.1.11+ Fix from $1,9502021-10-11 MEDIUM 5.3 CVE-2021-41831 It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users ar… Openoffice 4.1.11+ Fix from $1,6002021-10-11 HIGH 8.8 CVE-2021-29108 There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a rem… Portal For Arcgis after 10.9 Fix from $1,9502021-10-01 HIGH 7.3 CVE-2021-31841 A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsig… Mcafee Agent 5.7.4+ Fix from $1,9502021-09-22 HIGH 7.8 CVE-2021-31847 Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL… Agent 5.7.4+ Fix from $1,9502021-09-22 CRITICAL 9.8 CVE-2021-37927 Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-09-22 MEDIUM 6.4 CVE-2021-34709 Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NC… Ios Xr 7.3.2 / 7.4.1+ Fix from $1,6002021-09-09 MEDIUM 6.7 CVE-2021-34708 Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NC… Ios Xr 7.3.2 / 7.4.1+ Fix from $1,6002021-09-09 HIGH 8.1 CVE-2021-3051 An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-… Cortex Xsoar Mitigation only Fix from $1,9502021-09-08 HIGH 7.5 CVE-2021-1849 An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchO… Ipados 7.4 / 11.3+ Fix from $1,9502021-09-08