Vulnerabilities > Improper Verification of Cryptographic Signature

DATE CVE VULNERABILITY TITLE RISK
2024-12-18 CVE-2024-39804 A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS.
local
low complexity
CWE-347
7.1
2024-12-18 CVE-2024-41138 A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS.
local
low complexity
CWE-347
7.1
2024-12-18 CVE-2024-41145 A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS.
local
low complexity
CWE-347
7.1
2024-12-18 CVE-2024-41159 A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS.
local
low complexity
CWE-347
7.1
2024-12-18 CVE-2024-41165 A library injection vulnerability exists in Microsoft Word 16.83 for macOS.
local
low complexity
CWE-347
7.1
2024-11-12 CVE-2024-40592 Improper Verification of Cryptographic Signature vulnerability in Fortinet Forticlient
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.
local
high complexity
fortinet CWE-347
6.7
2024-11-12 CVE-2024-49394 Improper Verification of Cryptographic Signature vulnerability in multiple products
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
network
low complexity
neomutt mutt redhat CWE-347
5.3
2024-11-12 CVE-2024-49393 Improper Verification of Cryptographic Signature vulnerability in multiple products
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.
network
high complexity
neomutt mutt redhat CWE-347
5.9
2024-10-10 CVE-2024-9487 Improper Verification of Cryptographic Signature vulnerability in Github Enterprise Server
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance.
network
low complexity
github CWE-347
critical
9.1
2024-10-10 CVE-2024-48949 Improper Verification of Cryptographic Signature vulnerability in Indutny Elliptic
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
network
low complexity
indutny CWE-347
critical
9.1