Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2014-3585
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
Redhat Upgrade Tool
Mitigation only
HIGH 8.8
CVE-2019-3465
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatur…
Debian Linux
after 3.0.3
HIGH 7.8
CVE-2019-0071
Veriexec is a kernel-based file integrity subsystem in Junos OS that ensures only authorized binaries are able to be executed. Due to a flaw in speci…
Junos
Mitigation only
HIGH 7.5
CVE-2019-16992
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency at…
Keybase
Mitigation only
HIGH 7.5
CVE-2019-11755
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, althoug…
Thunderbird
68.1.1+
MEDIUM 6.7
CVE-2019-12662
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege …
Ios Xe
Mitigation only
MEDIUM 6.7
CVE-2019-12649
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicio…
Ios Xe
Mitigation only
MEDIUM 6.5
CVE-2019-3738
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could p…
Bsafe Cert J
6.2.5+
HIGH 7.5
CVE-2019-15545
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.
Libp2p
0.8.1+
MEDIUM 5.9
CVE-2019-5592
Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine versi…
Fortios Ips Engine
after 5.00006
HIGH 7.5
CVE-2019-9153
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with…
Openpgpjs
after 4.1.2
HIGH 7.5
CVE-2019-9154
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.
Openpgpjs
after 4.1.2
HIGH 8.1
CVE-2019-10201
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response …
Keycloak
after 6.0.1
HIGH 7.8
CVE-2019-5299
Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vulnerability. Attackers can indu…
Hima Al00b Firmware
Mitigation only
HIGH 7.8
CVE-2019-2278
User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto, Snapdragon Consumer IOT, Snap…
Mdm9607 Firmware
Patch available
CRITICAL 9.8
CVE-2019-1010161
perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT sec…
Perl Crypt Jwt
after 0.022
HIGH 7.5
CVE-2019-1010279
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An…
Suricata
4.1.3+
CRITICAL 9.8
CVE-2019-1010263
Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token…
\
0.023+
MEDIUM 6.5
CVE-2019-9149
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an …
Mailvelope
3.3.0+
CRITICAL 9.8
CVE-2019-13177
verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the D…
Django Rest Registration
0.5.0+
MEDIUM 6.7
CVE-2019-5300
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 a…
Ar1200 Firmware
Mitigation only
MEDIUM 5.9
CVE-2019-11841
A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to t…
Crypto
No fix yet
HIGH 7.5
CVE-2019-12269
Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" me…
Enigmail
2.0.11+
MEDIUM 5.9
CVE-2019-8338
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, w…
Gpg Pgp
after 1.0
MEDIUM 5.9
CVE-2018-12556
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrar…
Website
after 2018-06-05
MEDIUM 6.7
CVE-2019-1809
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…
Nx Os
3.2 / 7.3+
MEDIUM 6.7
CVE-2019-1810
A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could al…
Nx Os
7.0 / 9.2+
MEDIUM 6.7
CVE-2019-1811
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…
Nx Os
7.0 / 9.2+
MEDIUM 6.7
CVE-2019-1812
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…
Nx Os
7.0 / 9.2+
MEDIUM 6.7
CVE-2019-1813
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-l…
Nx Os
7.0 / 9.2+