Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

734 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2021-44878

Published Jan 6, 2022

If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an explicit configuration on its…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34420

Published Nov 11, 2021

The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-43572

Published Nov 9, 2021

The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attacker…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43571

Published Nov 9, 2021

The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitra…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43570

Published Nov 9, 2021

The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43569

Published Nov 9, 2021

The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43568

Published Nov 9, 2021

The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-39909

Published Nov 5, 2021

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41832

Published Oct 11, 2021

It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised t…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-41831

Published Oct 11, 2021

It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-41830

Published Oct 11, 2021

It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. User…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-29108

Published Oct 1, 2021

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker wh…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31847

Published Sep 22, 2021

Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsig…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31841

Published Sep 22, 2021

A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name a…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3051

Published Sep 8, 2021

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific k…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 734 CVEsPage 20 of 30