Vulnerabilities > Improper Verification of Cryptographic Signature

DATE CVE VULNERABILITY TITLE RISK
2020-07-06 CVE-2020-9226 Improper Verification of Cryptographic Signature vulnerability in Huawei P30 Firmware
HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability.
network
huawei CWE-347
4.3
2020-07-02 CVE-2020-15091 Improper Verification of Cryptographic Signature vulnerability in Tendermint
TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block.
network
low complexity
tendermint CWE-347
4.0
2020-06-29 CVE-2020-2021 Improper Verification of Cryptographic Signature vulnerability in Paloaltonetworks Pan-Os
When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources.
network
paloaltonetworks CWE-347
critical
9.3
2020-06-26 CVE-2020-9047 Improper Verification of Cryptographic Signature vulnerability in Johnsoncontrols products
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior.
network
low complexity
johnsoncontrols CWE-347
critical
9.0
2020-06-22 CVE-2020-14966 Improper Verification of Cryptographic Signature vulnerability in multiple products
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js.
network
low complexity
jsrsasign-project netapp CWE-347
7.5
2020-06-16 CVE-2020-14199 Improper Verification of Cryptographic Signature vulnerability in Satoshilabs Trezor Model T Firmware and Trezor ONE Firmware
BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee.
4.3
2020-06-07 CVE-2020-13895 Improper Verification of Cryptographic Signature vulnerability in P5-Crypt-Perl Project P5-Crypt-Perl
Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1.
6.8
2020-06-04 CVE-2019-20837 Improper Verification of Cryptographic Signature vulnerability in Foxitsoftware Phantompdf and Reader
An issue was discovered in Foxit Reader and PhantomPDF before 9.5.
5.0
2020-06-04 CVE-2019-20834 Improper Verification of Cryptographic Signature vulnerability in Foxitsoftware Phantompdf
An issue was discovered in Foxit PhantomPDF before 8.3.10.
5.0
2020-06-04 CVE-2020-13810 Improper Verification of Cryptographic Signature vulnerability in Foxitsoftware Phantompdf
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2.
network
low complexity
foxitsoftware CWE-347
5.0