VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (810)

page 40 of 41
  • CVE-2023-51765MedDec 24, 2023
    risk 0.00cvss 5.3epss 0.01

    sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports…

  • CVE-2023-42816MedNov 13, 2023
    risk 0.00cvss 6.1epss 0.00

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno…

  • CVE-2017-20180MedMar 6, 2023
    risk 0.00cvss 4.6epss 0.00

    A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the function CoinSpend::CoinSpend of the file CoinSpend.cpp of the component Proof Handler. The manipulation leads to insufficient verification of data authenticity. Continious delivery…

  • CVE-2021-4122MedAug 24, 2022
    risk 0.00cvss 4.3epss 0.00

    It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the…

  • CVE-2022-29220MedMay 31, 2022
    risk 0.00cvss 6.5epss 0.00

    github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the proper GPG key. There is just a check…

  • CVE-2022-24889LowApr 27, 2022
    risk 0.00cvss 2.4epss 0.01

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server that they do not need, thus expanding…

  • CVE-2021-43616CriNov 13, 2021
    risk 0.00cvss 9.0epss 0.03

    The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was…

  • CVE-2021-38597MedAug 12, 2021
    risk 0.00cvss 5.9epss 0.00

    wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.

  • CVE-2021-28678MedJun 2, 2021
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.

  • CVE-2021-31783HigApr 26, 2021
    risk 0.00cvss 7.5epss 0.01

    show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.

  • CVE-2020-25019HigAug 29, 2020
    risk 0.00cvss 7.5epss 0.01

    jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

  • CVE-2020-10751MedMay 26, 2020
    risk 0.00cvss 6.1epss 0.00

    A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the…

  • CVE-2019-15162MedOct 3, 2019
    risk 0.00cvss 5.3epss 0.02

    rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.

  • CVE-2019-10181HigJul 31, 2019
    risk 0.00cvss 8.1epss 0.01

    It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

  • CVE-2019-1000013HigFeb 4, 2019
    risk 0.00cvss 8.8epss 0.01

    Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from…

  • CVE-2019-1000012HigFeb 4, 2019
    risk 0.00cvss 8.8epss 0.01

    Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from…

  • CVE-2017-1000424MedJan 2, 2018
    risk 0.00cvss 4.3epss 0.01

    Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.

  • CVE-2015-2908Aug 23, 2015
    risk 0.00cvss —epss 0.02

    Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server.

  • CVE-2015-3908Aug 12, 2015
    risk 0.00cvss —epss 0.01

    Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2015-4674Aug 7, 2015
    risk 0.00cvss —epss 0.01

    The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieved without use of SSL, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.