The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(s
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowe
DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into
cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type o
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper
Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe comp
Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote att
Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wirel
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Mani
Windows Cryptographic Services Security Feature Bypass Vulnerability
Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. Thi
Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connec
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows
Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vuln
A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed tr
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Clien
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version
Secure Boot Security Feature Bypass Vulnerability
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A spec
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Exp
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platfo
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers t
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can levera
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.27
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Wor
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverag
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Ex
Windows Enroll Engine Security Feature Bypass Vulnerability
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an aut
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute p
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path re
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker tha
Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrar
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature v
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositori
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify functio
Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an a
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exp
whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload va
An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a priv
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started