Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

734 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2024-23456

Published Aug 6, 2024

Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28806

Published Aug 6, 2024

An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42461

Published Aug 2, 2024

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-42459

Published Aug 2, 2024

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appe…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41258

Published Jul 31, 2024

An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41254

Published Jul 31, 2024

An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive informa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5912

Published Jul 10, 2024

An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted e…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-6580

Published Jul 8, 2024

The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-20892

Published Jul 2, 2024

Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for trigg…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37532

Published Jun 20, 2024

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36277

Published Jun 17, 2024

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect even…

CVSS 5.3 · Medium

CVE-2024-21988

Published Jun 14, 2024

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vuln…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37886

Published Jun 14, 2024

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32911

Published Jun 13, 2024

There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-37568

Published Jun 9, 2024

lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asym…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2451

Published May 28, 2024

Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to further elev…

CVSS 6.4 · Medium

CVE-2024-1721

Published May 21, 2024

Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.

CVSS 5.6 · Medium

CVE-2024-34358

Published May 14, 2024

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageCo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50228

Published May 3, 2024

Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32962

Published May 2, 2024

xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only check…

CVSS 10.0 · Critical

CVE-2024-23480

Published May 1, 2024

A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27247

Published Apr 9, 2024

Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 734 CVEsPage 13 of 30