Vulnerabilities > Improper Verification of Cryptographic Signature

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-23460 Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed.
local
low complexity
zscaler CWE-347
7.8
2024-08-02 CVE-2024-42461 Improper Verification of Cryptographic Signature vulnerability in Elliptic Project Elliptic 6.5.6
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
network
low complexity
elliptic-project CWE-347
critical
9.1
2024-07-31 CVE-2024-41254 Improper Verification of Cryptographic Signature vulnerability in Litestream
An issue was discovered in litestream v0.3.13.
network
high complexity
litestream CWE-347
5.3
2024-07-31 CVE-2024-41258 Improper Verification of Cryptographic Signature vulnerability in Filestash
An issue was discovered in filestash v0.4.
network
high complexity
filestash CWE-347
5.3
2024-07-02 CVE-2024-20892 Improper Verification of Cryptographic Signature vulnerability in Samsung Android 12.0/13.0/14.0
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors.
local
low complexity
samsung CWE-347
7.8
2024-06-20 CVE-2024-37532 Improper Verification of Cryptographic Signature vulnerability in IBM Websphere Application Server 8.5.0.0/9.0.0.0
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation.
network
low complexity
ibm CWE-347
8.8
2024-06-14 CVE-2024-21988 Improper Verification of Cryptographic Signature vulnerability in Netapp Storagegrid
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.
network
high complexity
netapp CWE-347
5.3
2024-06-09 CVE-2024-37568 Improper Verification of Cryptographic Signature vulnerability in Authlib
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys.
network
low complexity
authlib CWE-347
7.5
2024-02-13 CVE-2024-21491 Improper Verification of Cryptographic Signature vulnerability in Svix Svix-Webhooks
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared.
network
low complexity
svix CWE-347
6.5
2024-02-08 CVE-2024-1149 Improper Verification of Cryptographic Signature vulnerability in Snowsoftware Snow Inventory Agent
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2.
local
low complexity
snowsoftware CWE-347
5.5