Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

734 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2023-28113

Published Mar 16, 2023

russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20929

Published Mar 10, 2023

A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthen…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-20940

Published Feb 28, 2023

In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalation of privilege with no additi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25718

Published Feb 13, 2023

In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the sign…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23940

Published Feb 3, 2023

OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23928

Published Feb 1, 2023

reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header and payload data if the service…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23334

Published Jan 30, 2023

The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate priv…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-22742

Published Jan 20, 2023

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24025

Published Jan 20, 2023

CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46176

Published Jan 11, 2023

Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36563

Published Dec 28, 2022

XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control ove…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23540

Published Dec 22, 2022

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47549

Published Dec 19, 2022

An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to b…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 734 CVEsPage 17 of 30