A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, re
A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to byp
Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgra
In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issu
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issu
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issu
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoo
Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofi
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g.,
Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to b
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptograph
The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting
The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issu
Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was d
aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is t
Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12
xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerab
xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerab
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature componen
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.
tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML lo
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function chec
MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli
Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them wit
Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker
Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persist
xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuratio
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.
Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and servi
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downlo
Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the s
In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the
There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privi
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication wi
ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass a
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices c
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this v
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowe
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started