Vulnerabilities > Insufficient Verification of Data Authenticity

DATE CVE VULNERABILITY TITLE RISK
2019-11-13 CVE-2019-5246 Insufficient Verification of Data Authenticity vulnerability in Huawei Elle-Al00B Firmware
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability.
low complexity
huawei CWE-345
6.2
2019-11-12 CVE-2019-5229 Insufficient Verification of Data Authenticity vulnerability in Huawei P30 Firmware
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability.
low complexity
huawei CWE-345
6.2
2019-11-08 CVE-2019-18835 Insufficient Verification of Data Authenticity vulnerability in Matrix Synapse
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.
network
low complexity
matrix CWE-345
critical
9.8
2019-11-05 CVE-2019-8112 Insufficient Verification of Data Authenticity vulnerability in Magento
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
network
low complexity
magento CWE-345
7.5
2019-10-29 CVE-2019-3979 Insufficient Verification of Data Authenticity vulnerability in Mikrotik Routeros
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack.
network
low complexity
mikrotik CWE-345
7.5
2019-10-17 CVE-2019-6475 Insufficient Verification of Data Authenticity vulnerability in ISC Bind
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers.
network
low complexity
isc CWE-345
7.5
2019-10-03 CVE-2019-15162 Insufficient Verification of Data Authenticity vulnerability in Tcpdump Libpcap
rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.
network
low complexity
tcpdump CWE-345
5.3
2019-09-30 CVE-2019-10492 Insufficient Verification of Data Authenticity vulnerability in Qualcomm products
Boot image not getting verified by AVB in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 820, SD 820A, SDM439
local
low complexity
qualcomm CWE-345
7.8
2019-09-27 CVE-2019-11737 Insufficient Verification of Data Authenticity vulnerability in Mozilla Firefox
If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content.
network
low complexity
mozilla CWE-345
5.3
2019-09-19 CVE-2019-16398 Insufficient Verification of Data Authenticity vulnerability in Keeper K5 Firmware 20.1.0.25/20.1.0.63
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
low complexity
keeper CWE-345
6.8