Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Devscripts CRITICAL 9.8
CVE-2025-8454

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to …

Mitigation only
Fix from $2,300 2025-08-01
Debian Linux HIGH 7.5
CVE-2023-46234

browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on i…

Fix: 4.2.2+
Fix from $1,950 2023-10-26
Debian Linux HIGH 7.5
CVE-2021-28091

Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

Fix: 2.7.0+
Fix from $1,950 2021-06-04
Debian Linux HIGH 7.5
CVE-2021-33054

SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network ac…

Fix: 2.4.1 / 5.1.1+
Fix from $1,950 2021-06-04
Debian Linux HIGH 7.5
CVE-2021-30130

phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.

Fix: 2.0.31 / 3.0.7+
Fix from $1,950 2021-04-06
Debian Linux MEDIUM 6.5
CVE-2021-21239

PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vuln…

Fix: 6.5.0+
Fix from $1,600 2021-01-21
Debian Linux HIGH 8.8
CVE-2019-3465

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatur…

Fix: after 3.0.3
Fix from $1,950 2019-11-07
Debian Linux MEDIUM 6.5
CVE-2018-15587

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a va…

Fix: after 3.28.2
Fix from $1,600 2019-02-11
Debian Linux HIGH 7.5
CVE-2018-16151

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GM…

Fix: 5.7.0+
Fix from $1,950 2018-09-26
Debian Linux HIGH 7.5
CVE-2018-16152

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GM…

Fix: 5.7.0+
Fix from $1,950 2018-09-26
Debian Linux HIGH 8.8
CVE-2018-16515

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction…

Fix: 0.33.3.1+
Fix from $1,950 2018-09-18
Debian Linux HIGH 7.5
CVE-2016-1000342

In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible …

Fix: after 1.55
Fix from $1,950 2018-06-04
Debian Linux CRITICAL 9.8
CVE-2018-1000076

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $2,300 2018-03-13
Debian Linux HIGH 8.1
CVE-2018-7711

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, a…

Fix: 1.10.6 / 1.15.4+
Fix from $1,950 2018-03-05
Debian Linux MEDIUM 6.5
CVE-2018-0489

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatu…

Fix: 1.6.4 / 6.7.2+
Fix from $1,600 2018-02-27
Debian Linux HIGH 8.1
CVE-2017-18122

A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as v…

Fix: after 1.14.16
Fix from $1,950 2018-02-02
Debian Linux MEDIUM 6.5
CVE-2018-0486

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signature…

Fix: 1.6.3+
Fix from $1,600 2018-01-13
Debian Linux HIGH 7.5
CVE-2017-17847

An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment s…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.5
CVE-2017-17848

An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages becau…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Debian Linux HIGH 8.1
CVE-2017-16852

shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly conf…

Fix: 2.6.1+
Fix from $1,950 2017-11-16
Debian Linux HIGH 8.1
CVE-2017-16853

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly co…

Fix: 2.6.1+
Fix from $1,950 2017-11-16