Skip to main content

Vendor archive

ncipher CVEs

Beta · best-effort

11 CVEs tagged to vendor ncipher0 Critical, 1 High, 7 Medium, 3 Low, 0 Unrated.

CVE-2006-1116

Published Mar 9, 2006

The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0320

Published Nov 23, 2004

Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequ…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0063

Published Feb 17, 2004

The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1417

Published Dec 31, 2003

nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the ke…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0939

Published Oct 4, 2002

The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0940

Published Oct 4, 2002

domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, whi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0941

Published Oct 4, 2002

The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user abo…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1446

Published Aug 1, 2002

The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0081

Published Feb 12, 2001

swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to applica…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1