VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 31 of 41
  • CVE-2024-11696MedNov 26, 2024
    risk 0.35cvss 5.4epss 0.00

    The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation…

  • CVE-2023-46234MedOct 26, 2023
    risk 0.35cvss 6.5epss 0.01

    browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be…

  • CVE-2023-35373MedJul 11, 2023
    risk 0.35cvss 5.3epss 0.01

    Mono Authenticode Validation Spoofing Vulnerability

  • CVE-2023-28226MedApr 11, 2023
    risk 0.35cvss 5.3epss 0.01

    Windows Enroll Engine Security Feature Bypass Vulnerability

  • CVE-2023-23940MedFeb 3, 2023
    risk 0.35cvss 6.4epss 0.00

    OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signature`. As a result, any contract using…

  • CVE-2022-46176MedJan 11, 2023
    risk 0.35cvss 5.3epss 0.01

    Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been…

  • CVE-2022-23540MedDec 22, 2022
    risk 0.35cvss 6.4epss 0.01

    In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected if you do not specify algorithms in the…

  • CVE-2021-41831MedOct 11, 2021
    risk 0.35cvss 5.3epss 0.01

    It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.

  • CVE-2021-32738MedJul 2, 2021
    risk 0.35cvss 6.5epss 0.01

    js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transaction including verifying…

  • CVE-2021-21239MedJan 21, 2021
    risk 0.35cvss 6.5epss 0.01

    PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 that use the default CryptoBackendXmlSec1 backend and need to verify signed SAML documents are…

  • CVE-2021-21238MedJan 21, 2021
    risk 0.35cvss 6.5epss 0.01

    PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML…

  • CVE-2018-18689MedJan 7, 2021
    risk 0.35cvss 5.3epss 0.04

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations…

  • CVE-2018-18688MedJan 7, 2021
    risk 0.35cvss 5.3epss 0.01

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature…

  • CVE-2020-8133MedNov 9, 2020
    risk 0.35cvss 5.3epss 0.01

    A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

  • CVE-2020-16922MedOct 16, 2020
    risk 0.35cvss 5.3epss 0.01

    A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security…

  • CVE-2020-15091MedJul 2, 2020
    risk 0.35cvss 6.5epss 0.01

    TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time and restart it (**without changing chainID**). A malicious block proposer (even…

  • CVE-2020-12692MedMay 7, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.

  • CVE-2018-18509MedApr 26, 2019
    risk 0.35cvss 5.3epss 0.02

    A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an…

  • CVE-2018-10470MedJun 12, 2018
    risk 0.35cvss 5.3epss 0.01

    Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architectures stored in a fat binary. An attacker can maliciously craft a fat binary containing multiple…

  • CVE-2018-6459MedFeb 20, 2018
    risk 0.35cvss 5.3epss 0.01

    The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter.