Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
HIGH 7.5 CVE-2020-13810 An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-sta… Phantompdf 9.7.2+ Fix from $1,9502020-06-04 HIGH 7.5 CVE-2020-13803 An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypass via a modified file or a f… Phantompdf 4.0+ Fix from $1,9502020-06-04 MEDIUM 6.8 CVE-2020-3209 A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malic… Ios Xe Patch available Fix from $1,6002020-06-03 HIGH 7.5 CVE-2020-12607 An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. … Fastecdsa 2.1.2+ Fix from $1,9502020-06-02 HIGH 7.5 CVE-2020-13415 An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a con… Controller after 5.1 Fix from $1,9502020-05-22 CRITICAL 9.1 CVE-2020-9753 Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. Whale Browser Installer 2.6.88.19+ Fix from $2,3002020-05-20 HIGH 7.5 CVE-2020-12244 An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not p… Fedora after 4.3.0 Fix from $1,9502020-05-19 MEDIUM 6.5 CVE-2020-12042 Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a resul… Softpac Project after 9.6 Fix from $1,6002020-05-14 MEDIUM 5.7 CVE-2020-12046 Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to… Softpac Project after 9.6 Fix from $1,6002020-05-14 HIGH 8.8 CVE-2020-5407 Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. Wh… Spring Security 5.2.4 / 5.3.2+ Fix from $1,9502020-05-13 MEDIUM 5.4 CVE-2020-12692 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An atta… Ubuntu Linux 15.0.1+ Fix from $1,6002020-05-07 HIGH 8.1 CVE-2020-11539 An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE sec… Sf Rush Smart Band Firmware No fix yet Fix from $1,9502020-04-22 HIGH 7.8 CVE-2019-10575 Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer I… Sda845 Firmware Mitigation only Fix from $1,9502020-04-16 CRITICAL 9.8 CVE-2020-1026 A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic… Research Javascript Cryptography Library Patch available Fix from $2,3002020-04-15 MEDIUM 5.5 CVE-2020-8324 A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow uns… System Interface Foundation 1.2.184.31+ Fix from $1,6002020-04-14 HIGH 7.8 CVE-2016-11044 An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signa… Android Mitigation only Fix from $1,9502020-04-07 HIGH 7.5 CVE-2019-17561 The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional c… Netbeans after 11.2 Fix from $1,9502020-03-30 HIGH 7.5 CVE-2015-7336 MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 201… System Update after 5.07.0008 Fix from $1,9502020-03-27 CRITICAL 9.1 CVE-2019-20597 An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgesture allows arbitrary applications to read or modi… Android Mitigation only Fix from $2,3002020-03-24 HIGH 7.4 CVE-2020-2146 Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks. Mac after 1.1.0 Fix from $1,9502020-03-09 HIGH 7.5 CVE-2020-9283EPSS 21% golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh pack… Package Ssh No fix yet Fix from $1,9502020-02-20 MEDIUM 6.7 CVE-2020-3138 A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to inst… Enterprise Network Function Virtualization Infrastructure after 3.11.1 Fix from $1,6002020-02-19 CRITICAL 9.8 CVE-2020-6174 TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. The Update Framework after 0.12.1 Fix from $2,3002020-02-05 HIGH 7.5 CVE-2020-7906 In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in … Rider Mitigation only Fix from $1,9502020-01-30 HIGH 7.5 CVE-2020-5390 PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected… Ubuntu Linux 5.0.0+ Fix from $1,9502020-01-13 CRITICAL 9.1 CVE-2019-14859 A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver… Ceph Storage 0.13.3+ Fix from $2,3002020-01-02 HIGH 7.5 CVE-2019-19962 wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography. Wolfssl 4.3.0+ Fix from $1,9502019-12-25 HIGH 8.1 CVE-2019-16732 Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root use… Petalk Ai Firmware No fix yet Fix from $1,9502019-12-13 MEDIUM 5.9 CVE-2012-2092 A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG sign… Ubuntu Cobbler 2.2.2+ Fix from $1,6002019-12-06 HIGH 7.5 CVE-2019-16753 An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation… Decentralized Anonymous Payment System after 2019-08-26 Fix from $1,9502019-12-04