Skip to main content

CWE archive

CWE-354 CVEs

Programmatic archive

171 CVEs tagged with CWE-35411 Critical, 78 High, 75 Medium, 7 Low, 0 Unrated.

CVE-2023-28002

Published Nov 14, 2023

An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24404

Published Oct 19, 2023

Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this allows an active adversary to manipulate cleartext data in…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-45150

Published Oct 16, 2023

Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email address…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20233

Published Sep 13, 2023

A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) cond…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33668

Published Jul 12, 2023

DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36537

Published Jul 11, 2023

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30673

Published Jul 6, 2023

Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attackers to delete arbitrary directory using directory junction.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31439

Published Jun 13, 2023

An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31438

Published Jun 13, 2023

An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modificatio…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31437

Published Jun 13, 2023

An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33981

Published May 24, 2023

Briar before 1.4.22 allows attackers to spoof other users' messages in a blog, forum, or private group, but each spoofed message would need to be an exact duplicate of a legitimat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28386

Published May 22, 2023

Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a pri…

CVSS 8.6 · High

CVE-2023-30356

Published May 10, 2023

Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers to update the device with crafted firmware

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-15028

Published Mar 12, 2023

A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45142

Published Mar 6, 2023

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23119

Published Feb 2, 2023

The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X Radio firmware version 3.2.2 and earlier vulnerable…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 171 CVEsPage 4 of 7