Vulnerabilities > Improper Verification of Cryptographic Signature

DATE CVE VULNERABILITY TITLE RISK
2019-12-06 CVE-2012-2092 Improper Verification of Cryptographic Signature vulnerability in Canonical Ubuntu Cobbler
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.
network
high complexity
canonical CWE-347
5.9
2019-12-04 CVE-2019-16753 Improper Verification of Cryptographic Signature vulnerability in multiple products
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26.
7.5
2019-11-26 CVE-2011-3374 Improper Verification of Cryptographic Signature vulnerability in Debian Advanced Package Tool and Debian Linux
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
network
high complexity
debian CWE-347
3.7
2019-11-22 CVE-2014-3585 Improper Verification of Cryptographic Signature vulnerability in Redhat Enterprise Linux and Redhat-Upgrade-Tool
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
network
low complexity
redhat CWE-347
critical
9.8
2019-11-07 CVE-2019-3465 Improper Verification of Cryptographic Signature vulnerability in multiple products
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
8.8
2019-09-30 CVE-2019-16992 Improper Verification of Cryptographic Signature vulnerability in Keybase 2.13.2
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's personal position on the semantics of an attestation.
network
low complexity
keybase CWE-347
7.5
2019-09-27 CVE-2019-11755 Improper Verification of Cryptographic Signature vulnerability in Mozilla Thunderbird
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message.
network
low complexity
mozilla CWE-347
7.5
2019-09-25 CVE-2019-12662 Improper Verification of Cryptographic Signature vulnerability in Cisco products
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device.
local
low complexity
cisco CWE-347
6.7
2019-09-25 CVE-2019-12649 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS and IOS XE
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device.
local
low complexity
cisco CWE-347
6.7
2019-08-26 CVE-2019-15545 Improper Verification of Cryptographic Signature vulnerability in Libp2P
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust.
network
low complexity
libp2p CWE-347
7.5