VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 30 of 41
  • CVE-2025-43468MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

  • CVE-2025-43390MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

  • CVE-2025-43185MedJul 30, 2025
    risk 0.36cvss 5.5epss 0.00

    A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An app may be able to access protected user data.

  • CVE-2025-2866MedApr 27, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be…

  • CVE-2024-1721MedMay 21, 2024
    risk 0.36cvss epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.

  • CVE-2024-27247MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.

  • CVE-2023-41764MedSep 12, 2023
    risk 0.36cvss 5.5epss 0.01

    Microsoft Office Spoofing Vulnerability

  • CVE-2023-28228MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Windows Spoofing Vulnerability

  • CVE-2022-42793MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. An app may be able to bypass code signing checks.

  • CVE-2021-40326MedAug 29, 2022
    risk 0.36cvss 5.5epss 0.00

    Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.

  • CVE-2021-40045MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-0152MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-3421MedMay 19, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to…

  • CVE-2020-9226MedJul 6, 2020
    risk 0.36cvss 5.5epss 0.00

    HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper check signature of specific software package, an attacker may exploit this vulnerability to load a crafted software package to the…

  • CVE-2018-10407MedJun 13, 2018
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by…

  • CVE-2016-8021MedMar 14, 2017
    risk 0.36cvss 5.0epss 0.03

    Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input file.

  • CVE-2026-40941MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

  • CVE-2026-6329MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the MAC parsed from the PKCS#12 structure using a…

  • CVE-2025-68113MedDec 16, 2025
    risk 0.35cvss 6.5epss 0.00

    ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce,…

  • CVE-2025-55039MedOct 15, 2025
    risk 0.35cvss 6.5epss 0.00

    This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to…