Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

733 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 27 Low, 1 Unrated.

CVE-2021-3633

Published Aug 17, 2021

A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38195

Published Aug 8, 2021

An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve orde…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26100

Published Jul 9, 2021

A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to mani…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24020

Published Jul 9, 2021

A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35039

Published Jul 7, 2021

kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32738

Published Jul 2, 2021

js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in it…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23993

Published Jun 24, 2021

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an inva…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23992

Published Jun 24, 2021

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32685

Published Jun 16, 2021

tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3196

Published Jun 9, 2021

An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. When using federated identity management (authenticating vi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29500

Published Jun 4, 2021

bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33054

Published Jun 4, 2021

SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20487

Published May 26, 2021

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature ver…

CVSS 9.1 · Critical

CVE-2021-22160

Published May 26, 2021

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29455

Published Apr 19, 2021

Grassroot Platform is an application to make it faster, cheaper and easier to persistently organize and mobilize people in low-income communities. Grassroot Platform before master…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 733 CVEsPage 21 of 30