Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

733 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 27 Low, 1 Unrated.

CVE-2019-16992

Published Sep 30, 2019

The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11755

Published Sep 27, 2019

A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15545

Published Aug 26, 2019

An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5592

Published Aug 23, 2019

Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9154

Published Aug 22, 2019

Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9153

Published Aug 22, 2019

Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp"…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18407

Published Aug 2, 2019

cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010161

Published Jul 25, 2019

perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _deco…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-1010279

Published Jul 18, 2019

Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signatur…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1010263

Published Jul 17, 2019

Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9149

Published Jul 9, 2019

Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10136

Published Jul 2, 2019

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could mov…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11841

Published May 22, 2019

A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format spec…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12269

Published May 21, 2019

Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8338

Published May 16, 2019

The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers t…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 626-650 of 733 CVEsPage 26 of 30