Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

735 CVEs tagged with CWE-347131 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2023-36811

Published Aug 30, 2023

borgbackup is an opensource, deduplicating archiver with compression and authenticated encryption. A flaw in the cryptographic authentication scheme in borgbackup allowed an attac…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41037

Published Aug 29, 2023

OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed te…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40178

Published Aug 23, 2023

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times eve…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43171

Published Aug 22, 2023

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to inst…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39393

Published Aug 13, 2023

Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39392

Published Aug 13, 2023

Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40012

Published Aug 9, 2023

uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key U…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39969

Published Aug 9, 2023

uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashing sect…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39211

Published Aug 8, 2023

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via l…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32449

Published Jun 22, 2023

Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a maliciou…

CVSS 7.2 · High

CVE-2023-28602

Published Jun 13, 2023

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client compone…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-33959

Published Jun 6, 2023

notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34205

Published May 30, 2023

In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed vi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33185

Published May 26, 2023

Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebho…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25934

Published May 4, 2023

DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1204

Published May 3, 2023

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 735 CVEsPage 16 of 30